4 Replies Latest reply on Jun 10, 2015 10:40 AM by Karen Glynn

    Email domains display when whitelist is used and invalid domain is used for an account request

    Karen Glynn

      When use of whitelisted domains is enabled and populated, if a person requests an account who isn't from those domains, the whitelisted domains display on the log in page (email domains in red text on the screenshot below).  This is a weakness as if this was malicious use the person knows which are the good domains to try:

      display of whitelisted domains.png

      Can this be hidden at all (without turning off the use of the white list)?