Skip to content

Commit bcb26bb

Browse files
committed
minor stuff yes
1 parent e51cc17 commit bcb26bb

File tree

2 files changed

+26
-4
lines changed

2 files changed

+26
-4
lines changed

docs/getting-started/2-legal-mumbo-jumbo.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ their date of birth during registration to ensure compliance with privacy laws a
4848
the application if necessary.
4949

5050
Related legal resources:
51-
- Article 20 of the French law No. 2018-493 relative to protection of personal data, [Loi n° 2018-493, Article 20](https://legifrance.gouv.fr/affichTexte.do?cidTexte=JORFTEXT000037085952)
52-
- Article L.227-24 of the French Penal Code, [Article L.227-24 du Code Pénal](https://www.legifrance.gouv.fr/affichCodeArticle.do?cidTexte=LEGITEXT000006070719&idArticle=LEGIARTI000006418096)
53-
- Article 8 of the European General Data Protection Regulation (GDPR), [(EU) 2016/679, Article 8](https://eur-lex.europa.eu/eli/reg/2016/679)
54-
- US' Children's Online Privacy Protection Act (COPPA), [15 U.S.C. §§ 6502(a)](https://uscode.house.gov/view.xhtml?edition=prelim&req=granuleid%3AUSC-prelim-title15-section6502)
51+
- Loi n° 78-17 du 6 janvier 1978 relative à l'informatique, aux fichiers et aux libertés, Article 7-1 ([Légifrance](https://legifrance.gouv.fr/loda/article_lc/LEGIARTI000037087837/2018-06-22))
52+
- Article L.227-24 du Code Pénal ([Légifrance](https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000042193612/2020-08-01))
53+
- Article 8 of the European General Data Protection Regulation (GDPR; (EU) 2016/679) ([Europa](https://eur-lex.europa.eu/eli/reg/2016/679))
54+
- US' Children's Online Privacy Protection Act (COPPA; 15 U.S.C. §§ 6502(a)) ([United States Code](https://uscode.house.gov/view.xhtml?edition=prelim&req=granuleid%3AUSC-prelim-title15-section6502))

docs/rest-api/1-authentication.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,14 +79,36 @@ discretion. In this case, you'll always get the `DOB_PRIVACY_LAW` error, even if
7979
of birth.
8080

8181
## Email confirmation
82+
>warn
83+
> This endpoint must **not** be automated. Internal systems may catch abnormal activity and flag the account for
84+
> suspicious activity, requiring manual administrator review to unlock the account.
8285
8386
## Login
8487

8588
## Multi-factor authentication
89+
>warn
90+
> This endpoint must **not** be automated. Internal systems may catch abnormal activity and flag the account for
91+
> suspicious activity, requiring manual administrator review to unlock the account.
8692
8793
## Remote authentication
94+
Remote authentication lets you authenticate a device using an already authenticated one (for example, your phone).
95+
We'll refer to the device you are authenticating the "New device" and the authenticated device "Trusted device".
96+
97+
Depending on the settings or on the instructions from the Trusted device, the session may be limited (or remote
98+
auth may not be available). This is useful to quickly login to devices you do not trust without typing your
99+
password and only have limited access to prevent token hijacking.
100+
101+
### New device side (Part 1)
102+
### Trusted device side
103+
### New device side (Part 2)
88104

89105
## Password reset
106+
>warn
107+
> Those endpoints must **not** be automated. Internal systems may catch abnormal activity and flag the account for
108+
> suspicious activity, requiring manual administrator review to unlock the account.
109+
110+
### Request a reset
111+
### Execute a reset
90112

91113
## Logout
92114
To logout, the client simply drops the token and doesn't do anything more. There is no dedicated procedure to log out

0 commit comments

Comments
 (0)