Our end users get the password expiration email, click on the link and if they are not already logged in, they receive "access denied". The link looks like this:
tiffin-test,
Your password at Tiffin University will expire in less than 14 day(s).
Please go to https://dev.tiffin.edu/user/6816/password to change your
password.
This occurs for all user roles.
Comments
Comment #2
aohrvetpv commentedriwilliams,
Thanks for reporting this. It is the expected behavior. If the user logs in, they'll be taken to the page to the change their password.
I think this is bad user experience though. The "Access denied" makes it seem like something is not working correctly. It's probably not totally clear to the user that they need to log in.
Do you have any suggestions on how this might be improved?
One small improvement would be to change "Please go to ... to change your password." to "Please go to ... and log in to change your password." Adding "and log in" might make it clearer. Showing "Access denied" is the default for Drupal pages that require authentication.
Note that changing the default expiration warning message is possible via the administrative interface.
Comment #3
paulocsAs this issue is a support request an no answer was provided, I'm closing this issue.
Comment #4
paulocsComment #5
paulocsComment #6
paulocsComment #7
paulocs