Authentication Overview
User authentication, account access, and password management in SSAdmin
Overview
SSAdmin uses a secure authentication system to protect user data and ensure only authorized personnel can access student and administrative information. This section covers the complete authentication flow including login, account activation, and password management.
Authentication Methods
The application supports the following authentication workflows:
Email and Password Login
Standard authentication for existing users:
- Enter registered email address
- Enter password
- Optional "Remember Me" for extended sessions
- Secure session management
- Automatic redirect to dashboard
Use Case: Daily login for administrators who already have active accounts.
Accept Invitation (New Users)
Invitation-based account activation for new team members:
- Receive email invitation from administrator
- Click secure invitation link
- Set initial password
- Account automatically activated
- Immediate access granted
Use Case: Onboarding new staff members to SSAdmin.
Password Reset
Self-service password recovery:
- Request magic link via email
- Click secure link in email
- Set new password
- Automatic sign-in
Use Case: Users who forgot their password or need to change it for security reasons.
Key Features
Secure Authentication
Password Requirements:
- Minimum 8 characters
- At least one uppercase letter
- At least one lowercase letter
- At least one number
- Password strength indicator
Security Measures:
- Encrypted password storage
- Secure session tokens
- HTTPS-only transmission
- Token expiration (1 hour for password reset)
- Protection against brute force attacks
Session Management
Remember Me Option:
- Extended session duration
- Automatic re-login on return visits
- Secure token storage
Session Security:
- Automatic timeout after inactivity
- Secure logout functionality
- Session validation on each request
Common Workflows
First-Time User
- Receive Invitation: Administrator sends invitation email
- Access Link: Click invitation link from email
- Review Details: Verify name, email, and role
- Set Password: Create strong password
- Activate Account: Click "Activate Account"
- Start Using: Immediately access SSAdmin
Daily Staff Member
- Navigate to Login: Go to SSAdmin login page
- Enter Credentials: Email and password
- Check Remember Me: Optional for convenience
- Sign In: Click button to access dashboard
- Work: Access administrative features
- Sign Out: Log out when finished
Forgotten Password
- Attempt Login: Try to sign in but forgot password
- Click Link: "Forgot your Password?" link
- Enter Email: Provide registered email address
- Check Email: Look for magic link email
- Click Link: Open link from email
- Set Password: Create new password
- Complete: Automatic sign-in
Security Best Practices
For Users
Password Security:
- Use unique, strong passwords
- Don't share passwords with anyone
- Change password if compromised
- Enable "Remember Me" only on personal devices
Account Security:
- Log out when finished
- Don't save passwords in browsers on shared computers
- Report suspicious activity immediately
For Administrators
User Management:
- Only invite authorized personnel
- Revoke access when staff leaves
- Monitor failed login attempts
- Regular security audits
Related Topics
- Login - Sign in to your account
- Accept Invitation - Set up new account
- Forgot Password - Reset your password
- Reset Password - Set new password