# 1. Affiliate Login

User Type: **Affiliate**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 1. Affiliate Login

### 1.1 Email and Password Login
**What it does:** Lets the Affiliate sign in to their account using their registered email address and password. The Affiliate enters their credentials, and the platform verifies them and grants access to the affiliate portal. The login is available on web and mobile. This is the primary way the Affiliate accesses their account.

**Sub-features:**
- Sign in with registered email and password
- Credential verification
- Access to the affiliate portal on success
- Error message on invalid credentials
- Account lockout after repeated failed attempts
- Login available on web and mobile
- Login event logging (success, failure)
- Audit logging of the email and password login

**Affiliate User Journey:**
1. Affiliate opens the login screen.
2. Affiliate enters their registered email and password.
3. The platform verifies the credentials.
4. On success, the affiliate portal opens.
5. On failure, an error message is shown.
6. After repeated failed attempts, the account is locked.
7. Affiliate opens Profile → "Activity" and confirms the login events are recorded.

**Rules & Edge Cases:**
- The credentials are the registered email and password.
- An error message is shown on invalid credentials.
- The account is locked after repeated failed attempts.
- Login events (success, failure) are logged with the account and the timestamp.
- The email and password login is audit-logged with the account and the timestamp.

### 1.2 One-Time Password (OTP) Login
**What it does:** Lets the Affiliate sign in using a one-time password (OTP) sent to their registered email or phone. The Affiliate requests the OTP, enters it, and the platform verifies it and grants access. The OTP is single-use and expires after a short period. This provides a passwordless login option.

**Sub-features:**
- Request an OTP to the registered email or phone
- Enter the OTP to sign in
- OTP verification
- OTP is single-use
- OTP expires after a short period
- Resend OTP with a cooldown
- Login available on web and mobile
- Login event logging (requested, verified)
- Audit logging of the one-time password login

**Affiliate User Journey:**
1. Affiliate opens the login screen and selects OTP login.
2. Affiliate requests the OTP.
3. The OTP is sent to the registered email or phone.
4. Affiliate enters the OTP.
5. The platform verifies the OTP and grants access.
6. The OTP is single-use and expires after a short period.
7. Affiliate opens Profile → "Activity" and confirms the login events are recorded.

**Rules & Edge Cases:**
- The OTP is sent to the registered email or phone.
- The OTP is single-use.
- The OTP expires after a short period.
- A resend has a cooldown.
- Login events (requested, verified) are logged with the account and the timestamp.
- The one-time password login is audit-logged with the account and the timestamp.

### 1.3 Social Login
**What it does:** Lets the Affiliate sign in using a supported social account (e.g., Google). The Affiliate selects the social provider, authorizes the platform, and the platform creates or links the affiliate account and grants access. This provides a convenient login option.

**Sub-features:**
- Sign in with a supported social account
- Social provider authorization
- Account creation or linking on first social login
- Access to the affiliate portal on success
- Social account unlink option
- Login available on web and mobile
- Login event logging (authorized, linked)
- Audit logging of the social login

**Affiliate User Journey:**
1. Affiliate opens the login screen and selects social login.
2. Affiliate selects the social provider (Google).
3. Affiliate authorizes the platform.
4. The platform creates or links the affiliate account.
5. The affiliate portal opens.
6. Affiliate can unlink the social account later.
7. Affiliate opens Profile → "Activity" and confirms the login events are recorded.

**Rules & Edge Cases:**
- The social login uses a supported provider.
- The account is created or linked on first social login.
- The social account can be unlinked.
- Login events (authorized, linked) are logged with the account and the timestamp.
- The social login is audit-logged with the account and the timestamp.
