# 1.1 Secure Login & SSO

User Type: **Corporate**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 1.1 Secure Login & SSO

### 1.1.1 Email & Password Login
**What it does:** Lets the Corporate admin and employee users sign in with their email and password. Sessions are managed server-side so a user stays signed in across devices until they sign out or the session expires. This is the default entry point to the Corporate portal.

**Sub-features:**
- Email + password sign-in for Corporate admins and employees
- Persistent sessions with configurable expiry
- Password reset via time-limited email link
- Account lockout after 5 consecutive failed attempts
- Login available on web and mobile
- Login event logging (viewed)
- Audit logging of the email & password login

**Corporate User Journey:**
1. Corporate user opens the login screen on web or mobile.
2. User enters their registered email and password.
3. The system verifies the credentials.
4. On success, the user lands on the Corporate dashboard with an active session.
5. On a forgotten password, the user requests a reset and receives a time-limited email link.
6. After 5 consecutive failed attempts, the account is locked and the user is notified.
7. User opens Profile → "Activity" and confirms the login events are recorded.

**Rules & Edge Cases:**
- Credentials are verified against the stored password hash; plain-text passwords are never stored.
- A session remains valid until sign-out or the configured expiry, whichever comes first.
- Password reset links expire after 30 minutes and can be used once.
- The account is locked for 15 minutes after 5 consecutive failed attempts.
- Login events (viewed) are logged with the account and the timestamp.
- The email & password login is audit-logged with the account and the timestamp.

### 1.1.2 One-Time Password (OTP) Login
**What it does:** Lets the Corporate user sign in with a one-time password delivered by email or SMS instead of a password. The OTP is single-use and short-lived, so a compromised password alone is not enough to sign in.

**Sub-features:**
- OTP delivery via email or SMS
- 6-digit code with 5-minute validity
- Single-use enforcement
- Resend OTP with rate limiting
- OTP login available on web and mobile
- OTP login event logging (viewed)
- Audit logging of the OTP login

**Corporate User Journey:**
1. Corporate user selects "Sign in with OTP" on the login screen.
2. User enters their registered email or phone number.
3. The system sends a 6-digit OTP by email or SMS.
4. User enters the OTP within 5 minutes.
5. On success, the user lands on the Corporate dashboard.
6. If the code expires, the user requests a resend (rate-limited).
7. User opens Profile → "Activity" and confirms the OTP login events are recorded.

**Rules & Edge Cases:**
- An OTP is valid for 5 minutes and can be used exactly once.
- A used or expired OTP is rejected even if entered correctly.
- At most 3 OTPs can be sent per 10 minutes per account.
- OTP codes are never stored in plain text.
- OTP login events (viewed) are logged with the account and the timestamp.
- The OTP login is audit-logged with the account and the timestamp.

### 1.1.3 Single Sign-On (SSO)
**What it does:** Lets the Corporate user sign in through the organization's identity provider using SAML 2.0 or OIDC. Employees use their corporate credentials once and reach the platform without a separate password, reducing password fatigue and centralizing access control.

**Sub-features:**
- SAML 2.0 and OIDC provider support
- IdP metadata / configuration setup by the Corporate admin
- Just-in-time account provisioning on first SSO login
- Session mapping between IdP and the platform
- SSO available on web and mobile
- SSO login event logging (viewed)
- Audit logging of the SSO login

**Corporate User Journey:**
1. Corporate admin configures the IdP (SAML 2.0 or OIDC) under Settings → SSO.
2. Employee opens the login screen and selects "Sign in with SSO".
3. The user is redirected to the corporate IdP and authenticates there.
4. On first login, the employee's account is provisioned just-in-time.
5. The user lands on the Corporate portal with a mapped session.
6. The admin can disable SSO, forcing a fallback to email + password.
7. User opens Profile → "Activity" and confirms the SSO login events are recorded.

**Rules & Edge Cases:**
- SSO is enabled per Corporate account by the Corporate admin.
- First SSO logins provision the account just-in-time using IdP attributes.
- If the IdP session is terminated, the platform session is terminated too.
- Disabling SSO does not delete accounts; email + password remains available.
- SSO login events (viewed) are logged with the account and the timestamp.
- The SSO login is audit-logged with the account and the timestamp.

### 1.1.4 Two-Factor Authentication
**What it does:** Adds a second verification step (authenticator app or SMS) on top of the primary credential for the Corporate admin and any user who enables it. This protects high-privilege accounts from credential theft.

**Sub-features:**
- TOTP authenticator app support
- SMS fallback factor
- QR code / secret key enrollment
- Backup codes (10 single-use)
- Mandatory 2FA option for Corporate admins
- 2FA available on web and mobile
- 2FA enrollment event logging (viewed)
- Audit logging of the two-factor authentication

**Corporate User Journey:**
1. Corporate user opens Settings → Security → Two-Factor Authentication.
2. User scans the QR code with an authenticator app (or selects SMS).
3. User enters the 6-digit code to confirm enrollment.
4. The system generates 10 single-use backup codes.
5. On the next sign-in, the user enters the code after the password.
6. If the device is lost, the user signs in with a backup code.
7. User opens Profile → "Activity" and confirms the 2FA events are recorded.

**Rules & Edge Cases:**
- 2FA requires a valid primary credential first.
- Backup codes are single-use; each code is invalidated after one use.
- When mandatory 2FA is on, Corporate admins cannot sign in without it.
- Disabling 2FA requires re-entering the current password.
- 2FA enrollment events (viewed) are logged with the account and the timestamp.
- The two-factor authentication is audit-logged with the account and the timestamp.
