Problem/Motivation
Password Policy 8.x-3.0 Stable release which covered by the Drupal Security Team was released 30 June 2021
https://www.drupal.org/project/password_policy/releases/8.x-3.0
The following used patches were committed into the version
- #2971079: Can't edit user profile because password policy validates even when password unchanged
- #3154140: Only force password change if new policies are applicable
- #3153875: PasswordPolicyValidator detects role change when there isn't one
Proposed resolution
- Update the Password Policy module to stable 3.0
- Remove committed patches
It was updated on the 9.0.x branch. But not in the 8.x-8.x one
#3222221: Update Password Policy module from 3.0-beta1 to ~3.0 and remove committed patches
Remaining tasks
- ✅ File an issue about this project
- ✅ Update and remove committed patches
- ✅ Testing to ensure no regression
- ❌ Automated unit/functional testing coverage
- ✅ Developer Documentation support on feature change/addition
- ❌ User Guide Documentation support on feature change/addition
- ✅ Code review from 1 Varbase core team member
- ✅ Full testing and approval
- ✅ Credit contributors
- ✅ Review with the product owner
- ✅ Quick Release Varbase Core 8.x-8.34
User interface changes
- None
Navigate to "admin/config/security/password-policy/default_policy/constraint"

API changes
- None
Data model changes
- None
| Comment | File | Size | Author |
|---|---|---|---|
| #16 | Configure-Constraints---Policy-Constraints--varbase_security--dev-Varbase8c1.png | 108.75 KB | rajab natshah |
| #7 | 3231956-7.patch | 1.16 KB | rajab natshah |
| #2 | update-password-policy-module-3231956-2.patch | 1.04 KB | yousefanbar |
Comments
Comment #2
yousefanbar commentedComment #3
rajab natshahComment #4
rajab natshahComment #5
rajab natshahIt was updated on the 9.0.x branch. But not in the 8.x-8.x one
#3222221: Update Password Policy module from 3.0-beta1 to ~3.0 and remove committed patches
Comment #6
rajab natshahRemoving the following patch too
#3154140: Only force password change if new policies are applicable
As it was fixed in
#3153875: PasswordPolicyValidator detects role change when there isn't one
Comment #7
rajab natshahComment #8
rajab natshahComment #10
rajab natshahComment #11
rajab natshahComment #12
rajab natshahComment #13
rajab natshahComment #14
rajab natshahComment #15
rajab natshahComment #16
rajab natshahComment #17
rajab natshahComment #18
rajab natshahComment #19
rajab natshahComment #20
rajab natshahComment #21
rajab natshah