Problem/Motivation
When `restrict_password_management` is enabled in CAS settings and a CAS-linked user accesses their profile edit form (user/{uid}/edit) via a one-time login link (e.g. from a notification email), submitting the form produces:
"Password field is required."
Steps to reproduce
- Enable CAS with "Restrict password management" turned on.
- Create a CAS-linked user account.
- Generate a one-time login URL for the user (user/{uid}/reset/{timestamp}/{hash}).
- Visit the URL and click "Log in".
- You are redirected to user/{uid}/edit with a pass-reset-token query parameter.
- Press "Save" without changing anything.
Drupal core's AccountForm sets `$form['account']['pass']['#required'] = TRUE` when `$form_state->get('user_pass_reset')` is TRUE (i.e. when arriving via a one-time login link). See AccountForm::form(), around the user_pass_reset block.
cas_form_user_form_alter() correctly sets `$form['account']['pass']['#access'] = FALSE` when restrict_password_management is enabled, but does not clear `#required`.
Issue fork cas-3596492
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
alorencComment #4
saidatomFor me it looks ok. RTBC.
Comment #7
claudiu.cristeaMerged. Thank you!