Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DOC-2278: Combine Login and Password Policies; add Password Policy rules to Configuration Parameters (4.1) #513

Open
wants to merge 26 commits into
base: 4.1
Choose a base branch
from

Conversation

zhihuapengtg
Copy link
Contributor

@zhihuapengtg zhihuapengtg commented Sep 2, 2024

DOC-2103 configuration-parameters about password policy
DOC-2278 Improv: Combine Login and Password Policies into one section

@zhihuapengtg zhihuapengtg changed the title Update configuration-parameters.adoc [DOC-2103][DOC-2278] Update configuration-parameters.adoc Sep 2, 2024
@zhihuapengtg zhihuapengtg changed the title [DOC-2103][DOC-2278] Update configuration-parameters.adoc Update configuration-parameters.adoc & Improv: Combine Login and Password Policies into one section Sep 2, 2024
@zhihuapengtg
Copy link
Contributor Author

@arun-TG-PM @victorleeTG Please help review this PR for the comment: https://graphsql.atlassian.net/browse/DOC-2103?focusedCommentId=167492, thanks!

@arun-TG-PM arun-TG-PM self-requested a review September 5, 2024 07:43
@victorleeTG victorleeTG changed the title Update configuration-parameters.adoc & Improv: Combine Login and Password Policies into one section DOC-2278: Combine Login and Password Policies; add Password Policy rules to Configuration Parameters Oct 18, 2024
@victorleeTG victorleeTG changed the title DOC-2278: Combine Login and Password Policies; add Password Policy rules to Configuration Parameters DOC-2278: Combine Login and Password Policies; add Password Policy rules to Configuration Parameters (4.1) Oct 18, 2024
@victorleeTG victorleeTG added the doc improv Improvements or additions to documentation label Oct 18, 2024
== Login Protection

Login protection is a security feature that helps safeguard user accounts from unauthorized access, enhancing overall account security.
See xref:tigergraph-server:security:login-protection[] for a detailed description
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
See xref:tigergraph-server:security:login-protection[] for a detailed description
See xref:login-protection[] for a detailed description

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If referencing a page within the same component/repo, do not give the name of the component.
The reason why is: referencing the component with jump to the newest version of that component (if you didn't specify a version).

:pp: {plus}{plus}
:page-aliases: README.adoc, readme.adoc

Tigergraph provides complexity password policy and login protection to improve the security.
Copy link
Collaborator

@anjaliIthapeTG anjaliIthapeTG Nov 13, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Tigergraph provides complexity password policy and login protection to improve the security.
TigerGraph provides a complex password policy and login protection to enhance security.

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@anjaliIthapeTG We don't have a complex policy (or at least I hope we don't). We offer optional built-in rules for the complexity of passwords, e.g. the password must have a letters, numbers, and special characters.

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@victorleeTG My apologies for the oversight. I’ll review the documentation mentioned on the website and will update again

:pp: {plus}{plus}
:page-aliases: README.adoc, readme.adoc

Tigergraph provides complexity password policy and login protection to improve the security.
Copy link
Collaborator

@anjaliIthapeTG anjaliIthapeTG Nov 13, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could also include reasons why a complex password policy and login protection are necessary and how can it help users

@@ -1,7 +1,9 @@
= Password Policy
:description: Overview of password policy.

This guide provides instructions on how to configure and enforce password complexity policies.
The password policy allows administrators to flexibly set rules that must be followed when creating passwords, including password expiration, password rotation rules, and password complexity requirements. The purpose of this policy is to enhance system security, as administrators can establish different levels of password complexity requirements to reduce the risks of unauthorized access and data breaches. Through the password policy, the system can promote secure password management practices and strengthen overall system security.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

On Page "login-password","Password Policy" section provides the definition of a password policy, and the above i.e. "Password Policy" section under page "password-policy" ,explains its purpose. Rather than giving two different explanations, we can combine them into one comprehensive statement that defines the policy and highlights its importance in enhancing security.

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agree that we should provide a unified overview of the features and benefits. It is reasonable to say a few words about the benefits, but I consider the purpose of password rules to be quite obvious to the general reader. Every consumer has passwords and has been affected by password rules. Including a sentence about the benefits will be good for search engine ranking, though.

Copy link
Collaborator

@anjaliIthapeTG anjaliIthapeTG left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It would be easier for users to understand if, on the login-password page, we mention the importance of password policy and login protection and on the login-protection page, we should solely mention the importance of login protection along with all the basic definitions. Similarly, we can do the same with the password-policy page.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
doc improv Improvements or additions to documentation
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants