Problem/Motivation
When a user login with one-time login token, then clicks around, this module redirects the user back to the profile page. However, because the one-time login token is not in the URL parameter anymore, the core AccountForm would require the user to type in the "Current password", which the user might not have. Therefore, the user cannot save the form, but request another one-time login token.
The UX is worse, when the site is configured to "Require email verification when a visitor creates an account", in which the user only sets the password after they login with one-time token. Therefore, if the redirect happens, the user cannot save the form without the current password.
Steps to reproduce
Proposed resolution
Check the user session, if there is pass_reset_USER_ID, then we redirect the user to the profile page with the one-time token.
Remaining tasks
User interface changes
API changes
Data model changes
| Comment | File | Size | Author |
|---|---|---|---|
| #2 | 3264632-2.patch | 1.22 KB | skyredwang |
Comments
Comment #2
skyredwangThe patch below is on top of #3259820: Support custom whitelist, so you probably will see automated build failing. Once that feature is committed, I can re-roll this patch
Comment #4
cosolom commentedThank you, commited
Comment #7
joekersThe pass_reset_UID never seems to be in the session so this isn't working for me. Am I missing something, or maybe there was a change to core that removes it from the $_SESSION?
Comment #8
cosolom commentedMaybe it's core related. Which Drupal version do you use? You can create new issue for this
Comment #9
joekers