-2

Login improvements

Tobi 9 years ago updated by Don 9 years ago 1

The Website Login UI could use some improvements


1. Wrong translation

Image 9
"Pin darf gleich 4 Zeichen sein." means "Pin can be 4 characters".
Which is misleading in the context of a wrong entered pin.

2. Wrong pin message

Image 10

If I enter a wrong ping the error message appears which is a little confusing, because I entered 4 digits, first I checked if I accidentally added some white space and tried multiple times.

3. Security

- The website should not distinguish between wrong pin an username, because currently i can check if the username exists, if I only get a pin error.

- I tried some PINs and didn't encounter any rate limiting, this should be mandatory with 4 digit pins, especially if it is possible to determine if the username already exists.
Just some suggestions, aside from this I very happy with the App/Website.
Best regards
Tobi





IMO no need to make it more complicated - after all it's a shopping list, not a banking app :-)