Quantcast
Viewing all articles
Browse latest Browse all 2648

[3.3.x] Support Forum • Re: Can I force new users to change their password upon initial login?

Side Note:
As stated above, users don't get prompted to change their password. But me already logged in as an admin get forced *sometimes* to change MY password via UCP > Profile > Edit account settings.
Doesn't happen every time and I'm not sure of the exact sequence of events so I can't reproduce it. It has happened on two newish boards. One that I'm preparing for users and production. And another solely as a test system.
I think I understand this behavior now. There are two places you can set Force password change: and the last one to be set changes the value for both places. Since I was setting it to 1(day) the password change requirement for me logged in as admin were coming at a seemingly random time.

ACP > BOARD CONFIGURATION > User registration settings > Force password change:

and

ACP > SERVER CONFIGURATION > Security settings > Force password change:

As far as I can tell there isn't a Jira issue for this and unless I'm missing something there should be. I'd be happy to create one but would like someone with more experience weigh in on this before I create an incorrect issue and waste devs time.

As for my original question, I haven't figured out a workaround except to ask the users to change the password themselves(which is already in the email). Unless maybe when I create the users I use a ridiculously complex password that will encourage changing it.

I also tried the option of going to the login page and selected the 'I forgot my password', pretending I was the newly created user and it sent an email with the reset your password link. My test user could ignore the email and still login with the original password. So that didn't do any good.

Still trying to figure this out.

Statistics: Posted by gctaylor — Thu Feb 22, 2024 3:49 am



Viewing all articles
Browse latest Browse all 2648

Trending Articles