I am using "simpleSAMLphp Authentication" module to authenticate the user. As users using their SSO accounts to log in, drupal don't store any password. After enabling password policies, users are getting forced to change passwords even there are no password fields.

Expected behaviour:
1. If the user is going to log in with their SSO accounts, he should not be forced to update their passwords.
2. Password policy status table should not appear if there are no password fields.
3. Avoid updating password expiry field of SAML enabled users in cron.

Comments

omkar06 created an issue. See original summary.

omkar06’s picture

Issue summary: View changes
omkar06’s picture

Status: Active » Needs review
StatusFileSize
new2.48 KB

Adding a basic fix to handle SSO based users. Please review and share if there any better approach to handle it.

omkar06’s picture

omkar06’s picture

StatusFileSize
new529.06 KB
omkar06’s picture

Issue summary: View changes
aohrvetpv’s picture

Status: Needs review » Needs work

Thanks for the feature request and patch! Password Policy 7.x-1.x and 7.x-2.x have a feature that allows excluding selected authentication modules from password policies. Here is some of the code from 7.x-1.x:
https://git.drupalcode.org/project/password_policy/blob/7.x-1.x/password...

I think we should probably implement this in 8.x-3.x.

So I think your patch is the right idea, but that we shouldn't have any code specific to "simpleSAMLphp Authentication" in Password Policy, so we can accommodate all the many other authentication modules like "simpleSAMLphp Authentication".

aohrvetpv’s picture

It might be reasonable to commit code specific to that module (simpleSAMLphp Authentication) until we can implement the more general solution. Later we would just drop the module-specific code.

simbaw’s picture

Version: 8.x-3.x-dev » 8.x-3.0-beta1
Status: Needs work » Needs review
StatusFileSize
new1.43 KB

Make all SSO users skip password policy.

simbaw’s picture

Version: 8.x-3.0-beta1 » 8.x-3.0
StatusFileSize
new1.46 KB
rosk0’s picture

Version: 8.x-3.0 » 8.x-3.x-dev
Category: Task » Feature request
StatusFileSize
new4.24 KB
new0 bytes

Thanks for the idea @simbaw. I've used your approach, but improved implementation a bit.

Changes are :

  • Comments changed to reflect the actual checks - external authentication in general, rather then specific implementation (SAML )
  • FAPI validate callback lost return value
  • Added entry to the README about externally authenticated users
rosk0’s picture

StatusFileSize
new4.25 KB

Correct interdiff for the previous comment.

rosk0’s picture

Status: Needs review » Reviewed & tested by the community

Battle tested the patch from #12 - works like a charm! Thanks @simbaw - all credits should go there.

  • RoSk0 authored 35204f6 on 8.x-3.x
    Issue #3092396 by simbaw, omkar06, RoSk0, manish.upadhyay, AohRveTPV: Do...
paulocs’s picture

Status: Reviewed & tested by the community » Fixed

Thanks!

paulocs’s picture

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.