Hi,

I have enabled force password change module and it works fine, But I have found an issue that if a user forgot his password and he used forgot password link in drupal 8 to reset his/her password. A one time login url sent to his/her email id so that he/she can use link to reset his/her password. On the other hand admin also enable the checkbox ( Force this user to change their password) on user profile form to force this user to change his/her password. In this case when user click on one time login url(received on user's registered email) to reset his/her password, A form has been opened with current password field(which is an extra filed in this form, This field should not be displayed when user forgot his current password) and a message has been displayed on the top "An administrator has required that you change your password. Please change your password to proceed". Please take a look into this.

Thanks,

Comments

munishsharma created an issue. See original summary.

munish.kumar’s picture

Issue summary: View changes
munish.kumar’s picture

Issue summary: View changes
geophysicist’s picture

here is my patch. Should work

mangy.fox’s picture

StatusFileSize
new2.42 KB

If the user tries to navigate away from the initial "password reset"/"new user" edit page, they are redirected to the "standard" edit page with the current password field. To fix this I am checking for the presence of the "pass_reset_UID" token in the session. If this is present then the user is resetting the password and the token should be added to the URL.

beunerd’s picture

Nice! I can confirm that #5 works to keep the user on the edit form, while not requiring the 'current password' if using a one-time login link.

mangy.fox’s picture

Status: Active » Needs review
StatusFileSize
new3.02 KB

In testing it was discovered that whilst you couldn't navigate away from the page, there was nothing stopping you from submitting the form without changing the password. The validation handler doesn't seem to be working, but this wan't picked up because previously the update hook was only removing the pending status if current password was entered.

I have changed the check in the validation handler from 'force_password_change' to 'pending_force'. I'm not sure if 'force_password_change' is a real value, but 'pending_force' is the check that happens in the user update hook and seems to work as desired.

sean.walker@nreca.coop’s picture

@mangy.fox -- THANK YOU for this patch. I was previously using a module called No Current Password (nocurrent_pass) to hide the requirement for knowing the current password. Caveat was I was using it in combination with this module, which actually caused an infinite loop of requiring password reset whenever logging into the site. It was quite maddening, but I pm-uninstalled the nocurrent_pass module and then applied your patch and everything is 100% now. Wanted to provide these details in case anyone else is using nocurrent_pass and ran into the same issue. This patch should fix the user experience and workflow to the way it should be.

robcarr’s picture

Status: Needs review » Reviewed & tested by the community

Works a treat.

This fix has been around for 2 years so it would be good to commit ASAP

stefdewa’s picture

Rerolled patch against 2.0.x branch.

larisse’s picture

Version: 8.x-1.x-dev » 2.0.x-dev

This still a problem in 2.0.x version?

laisbonafe’s picture

Hi, I tested the functionality in 2.0.x version, and not have been errors

larisse’s picture

Status: Reviewed & tested by the community » Needs review
StatusFileSize
new3.75 KB

Hi!
I am able to reproduce this error in 2.0.x version.

Reroll from patch #10.

larisse’s picture

larisse’s picture

Assigned: Unassigned » larisse

I'll review this issue again...

  • larisse committed 653690f on 2.0.x authored by mangy.fox
    Issue #2922398 by mangy.fox, larisse, Stefdewa, geophysicist, sean....
larisse’s picture

Assigned: larisse » Unassigned
Status: Needs review » Fixed

Thank you everyone to working on this. =)
I committed in 2.0.x-dev version and I'll release a new version from this module soon.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.