In TM under "Transaction Details" there's a property "Save Challenge Failures". Is there a way to access this via an API? I was hoping to add a Form Security Filter that displays something else than the Save Challenge page on the form if they've reached their max attempts.
It would be even better if the error response that came back from the SaveChallenge event would give you this for a better experience.
Whilst this would make it more useable there is a balance with product security. Unfortunately for you the balance is firmly tipped in the product security camp.
We cant have save challenge leaking information about transactions to a potential attackers.
We regularly undergo penetration testing on client systems and have been picked up on similar issue. Implementing this on an existing system may mean that it would have to redo penetration testing.