SaaS Login Development

Job ID: 38388319

Budget: £250 – £750 GBP

We have a custom made SaaS which provides a front facing public website and a private facing website with additional features. We need to harden our login method for the private side.

Currently there is no lockout in place and no minimum password requirements have been set.

We would like a new login method to be introduce which takes security practices into consideration. To ensure user experience, we do not want to force MFA - but will like to give the option to the client to setup MFA if they'd like. We need the password-policy to be a minimum of 12 characters, with complexities and no re-use of old passwords. We would like to force password changes after 90 days. We would also like to introduce account lockout and disabling in the event of an account compromise. The lockout should be set to 15 minutes after 3 unsuccessful attempts, and then a further need for CAPTCHA to verify. We already have users created - they will need to reset their own passwords at the next login.

We would also like a separate portal which give us the ability of administrative tasks, particularly with users accounts, disabling user account, re-enabling user accounts, MFA resets and the ability to upload data directly to the correct folders. Currently, user creation and management is done by hardcode, and uploading of files is done directly with FTP, we need this to be simpler for an administrator to control.

Security is the top priority for this project - we need to be using best industry practices for all our code. The SaaS is setup on our Windows Server 2022, running GeoServer and WAMP stack. The software is made of HTML, JavaScript & PHP
Related categories: PHP Website Design Web Security MySQL HTML