There's room for more stuff like: requiresPasswordChange() should be true if current password is older than maximim allowed duration for one unchanged password
historyOfPreviousLoginAttempts(n) could return the last n login attemmpts with timestamp and challenge result But i don't think that all that stuff should go into the Authentication module. I tend to put the history in an Audit module. You are subscribed to cfcdev. To unsubscribe, please follow the instructions at http://www.cfczone.org/listserv.cfm CFCDev is supported by: Katapult Media, Inc. We are cool code geeks looking for fun projects to rock! www.katapultmedia.com An archive of the CFCDev list is available at www.mail-archive.com/[email protected]
