Hi,
I have enabled force password change module and it works fine, But I have found an issue that if a user forgot his password and he used forgot password link in drupal 8 to reset his/her password. A one time login url sent to his/her email id so that he/she can use link to reset his/her password. On the other hand admin also enable the checkbox ( Force this user to change their password) on user profile form to force this user to change his/her password. In this case when user click on one time login url(received on user's registered email) to reset his/her password, A form has been opened with current password field(which is an extra filed in this form, This field should not be displayed when user forgot his current password) and a message has been displayed on the top "An administrator has required that you change your password. Please change your password to proceed". Please take a look into this.
Thanks,
| Comment | File | Size | Author |
|---|---|---|---|
| #13 | 2922398-13.patch | 3.75 KB | larisse |
| #10 | force_password_change-unable_to_reset_password-2922398-10.patch | 4.08 KB | stefdewa |
| #7 | unable-to-reset-password-2922398-7.patch | 3.02 KB | mangy.fox |
Comments
Comment #2
munish.kumar commentedComment #3
munish.kumar commentedComment #4
geophysicist commentedhere is my patch. Should work
Comment #5
mangy.fox commentedIf the user tries to navigate away from the initial "password reset"/"new user" edit page, they are redirected to the "standard" edit page with the current password field. To fix this I am checking for the presence of the "pass_reset_UID" token in the session. If this is present then the user is resetting the password and the token should be added to the URL.
Comment #6
beunerd commentedNice! I can confirm that #5 works to keep the user on the edit form, while not requiring the 'current password' if using a one-time login link.
Comment #7
mangy.fox commentedIn testing it was discovered that whilst you couldn't navigate away from the page, there was nothing stopping you from submitting the form without changing the password. The validation handler doesn't seem to be working, but this wan't picked up because previously the update hook was only removing the pending status if current password was entered.
I have changed the check in the validation handler from 'force_password_change' to 'pending_force'. I'm not sure if 'force_password_change' is a real value, but 'pending_force' is the check that happens in the user update hook and seems to work as desired.
Comment #8
sean.walker@nreca.coop commented@mangy.fox -- THANK YOU for this patch. I was previously using a module called No Current Password (nocurrent_pass) to hide the requirement for knowing the current password. Caveat was I was using it in combination with this module, which actually caused an infinite loop of requiring password reset whenever logging into the site. It was quite maddening, but I pm-uninstalled the nocurrent_pass module and then applied your patch and everything is 100% now. Wanted to provide these details in case anyone else is using nocurrent_pass and ran into the same issue. This patch should fix the user experience and workflow to the way it should be.
Comment #9
robcarrWorks a treat.
This fix has been around for 2 years so it would be good to commit ASAP
Comment #10
stefdewa commentedRerolled patch against 2.0.x branch.
Comment #11
larisse commentedThis still a problem in 2.0.x version?
Comment #12
laisbonafe commentedHi, I tested the functionality in 2.0.x version, and not have been errors
Comment #13
larisse commentedHi!
I am able to reproduce this error in 2.0.x version.
Reroll from patch #10.
Comment #14
larisse commentedComment #15
larisse commentedI'll review this issue again...
Comment #17
larisse commentedThank you everyone to working on this. =)
I committed in 2.0.x-dev version and I'll release a new version from this module soon.