# 1. Parent Login

User Type: **Parent**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 1. Parent Login

### 1.1 Email and Password Login
**What it does:** Lets the Parent sign in to their account using their registered email address and password. The Parent enters their credentials on the login screen, and the platform verifies them and grants access to the Parent panel. The login is secure and the credentials are never stored in plain text.

**Sub-features:**
- Login with registered email and password
- Email format validation
- Password validation
- Error message for incorrect credentials
- Rate limiting on repeated failed attempts
- Account lockout after repeated failures
- Secure credential handling
- Login event logging (success, failure)
- Audit logging of the email and password login

**Parent User Journey:**
1. Parent opens the login screen and enters their email and password.
2. The platform validates the email format.
3. The platform verifies the credentials.
4. On success, the Parent is taken to the Parent panel.
5. On failure, an error message is shown.
6. After repeated failures, the account is locked.
7. Parent opens Profile → "Activity" and confirms the login events are recorded.

**Rules & Edge Cases:**
- The email must be in a valid format.
- Incorrect credentials show a generic error message.
- Repeated failed attempts are rate-limited.
- The account is locked after the platform's failure threshold.
- Login events (success, failure) are logged with the account and the timestamp.
- The email and password login is audit-logged with the account and the timestamp.

### 1.2 One-Time Password (OTP) Login
**What it does:** Lets the Parent sign in using a one-time password (OTP) sent to their registered email or phone. The Parent requests an OTP, enters the 6-digit code, and is verified. The OTP expires after a short window and can be regenerated. This provides a passwordless login option.

**Sub-features:**
- Request an OTP to the registered email or phone
- Enter the 6-digit OTP code
- OTP expiry (short window)
- Regenerate the OTP
- OTP attempt limit
- OTP verification
- OTP event logging (requested, verified, expired)
- Audit logging of the one-time password login

**Parent User Journey:**
1. Parent selects "Login with OTP" and requests a code.
2. The OTP is sent to the registered email or phone.
3. Parent enters the 6-digit code.
4. The platform verifies the OTP.
5. On success, the Parent is taken to the Parent panel.
6. If the OTP expires, Parent requests a new one.
7. Parent opens Profile → "Activity" and confirms the OTP events are recorded.

**Rules & Edge Cases:**
- The OTP is a 6-digit code.
- The OTP expires after the platform's window.
- The OTP has an attempt limit.
- A new OTP can be requested.
- OTP events (requested, verified, expired) are logged with the account and the timestamp.
- The one-time password login is audit-logged with the account and the timestamp.

### 1.3 Social Login
**What it does:** Lets the Parent sign in using a social account (Google, Apple). The Parent selects the social provider, authorizes the platform, and is signed in. On first use, the social account is linked to the Parent's platform account. This provides a convenient login option.

**Sub-features:**
- Sign in with a social account (Google, Apple)
- Social account authorization
- Link the social account on first use
- Social login event logging (authorized, linked)
- Unlink a social account
- Social login available on web and mobile
- Audit logging of the social login

**Parent User Journey:**
1. Parent selects "Login with Google" on the login screen.
2. The social provider authorization is shown.
3. Parent authorizes the platform.
4. On first use, the social account is linked to the Parent's account.
5. The Parent is taken to the Parent panel.
6. Parent can unlink the social account later.
7. Parent opens Profile → "Activity" and confirms the social login events are recorded.

**Rules & Edge Cases:**
- The social login uses the provider's authorization.
- The social account is linked on first use.
- A social account can be unlinked.
- Social login events (authorized, linked) are logged with the account and the timestamp.
- The social login is audit-logged with the account and the timestamp.
