Services Security Updates

Last updated on
30 April 2025

This page is used as documentation for Services Security. It is unfortunate that issues come up that affect Services, but running the latest version of Services should help mitigate any issues.

If you see an issue and think it is security related, please follow the instructions here

SA # - . Due to a bug in Services that was committed, all passwords that are registered through Services 3.7 and up would be set 1 ( users from July 30th, 2013). There is a long discussion about how it was fixed here. Services update 7401 will reset the passwords of users and this was required by the SA team for Drupal. That being said, there are examples of why you don't need to run this update. If any of the following applies to you, you may set the variable "services_skip_security_update_7401" to TRUE and then run the update.

  1. Users were never registered through Services Stock user resource.
  2. Services module was not enabled.
  3. Services user Resource was never enabled.
  4. You used a custom resource to create/register users.
  5. Your Drupal site with services enabled does not use core Drupal user module. IE, you have a SSO provider who handles registration.
  6. Site was never upgraded to Services 3.6 or beyond.

Help improve this page

Page status: Not set

You can: