Password login is the surface every attacker tries first. This release adds the controls an auditor expects to find around it.
Controls on the form login
- A second factor Time-based one-time passwords, enrolled from a QR code. A user's second factor can be reset, which invalidates the remembered-device cookies issued before the reset, and a failed code validation is slowed before it answers.
- Throttling After three failed attempts for a user name, the next attempt is delayed, five seconds by default.
- Single session An optional mode invalidates a user's other sessions on login, off by default.
- No password, no form login A user with no stored password can only authenticate through an external provider.
Federated sign-in
- SAML The name-identifier format is configurable per authenticator.
- JWT A token is accepted from a configurable query parameter or cookie, with a flag that decides whether a session is created.
- OAuth A logout endpoint redirects to the identity provider so the session ends on both sides.
Later releases moved the password hash to Argon2id, added the breach check on password change and risk-based login. This is the baseline they build on.