Cognito integrated UI - Content injection with /login endpoint

1

The /login endpoint could be used to produce a UI sign-in webpage with custom error messages. To do this you should simply add the loginErrorMessage variable in your GET request:

&loginErrorMessage=Account%20Blocked%0APlease%20send%20your%20Email%20and%20Password%20to%20xyz@abc.com%20to%20unblock%20your%20account.

(Note that this variable is not even reported in your official documentation )

Thisbehaviour could be exploited by an attacker to create URLs for phishing purposes.

Is there a way to set a static message? Or to disable the login error message?

Nuva
已提問 2 年前檢視次數 138 次
沒有答案

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南