Problem/Motivation

When `restrict_password_management` is enabled in CAS settings and a CAS-linked user accesses their profile edit form (user/{uid}/edit) via a one-time login link (e.g. from a notification email), submitting the form produces:
"Password field is required."

Steps to reproduce

  • Enable CAS with "Restrict password management" turned on.
  • Create a CAS-linked user account.
  • Generate a one-time login URL for the user (user/{uid}/reset/{timestamp}/{hash}).
  • Visit the URL and click "Log in".
  • You are redirected to user/{uid}/edit with a pass-reset-token query parameter.
  • Press "Save" without changing anything.

Drupal core's AccountForm sets `$form['account']['pass']['#required'] = TRUE` when `$form_state->get('user_pass_reset')` is TRUE (i.e. when arriving via a one-time login link). See AccountForm::form(), around the user_pass_reset block.
cas_form_user_form_alter() correctly sets `$form['account']['pass']['#access'] = FALSE` when restrict_password_management is enabled, but does not clear `#required`.

Issue fork cas-3596492

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

alorenc created an issue. See original summary.

alorenc’s picture

Assigned: alorenc » Unassigned
Status: Active » Needs review
saidatom’s picture

Status: Needs review » Reviewed & tested by the community

For me it looks ok. RTBC.

claudiu.cristea made their first commit to this issue’s fork.

claudiu.cristea’s picture

Status: Reviewed & tested by the community » Fixed

Merged. Thank you!

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.