Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

本地目录首次登录强制修改密码功能缺陷 #949

Open
neronkl opened this issue Mar 29, 2023 · 2 comments
Open

本地目录首次登录强制修改密码功能缺陷 #949

neronkl opened this issue Mar 29, 2023 · 2 comments
Assignees

Comments

@neronkl
Copy link
Contributor

neronkl commented Mar 29, 2023

用文字描述你遇到的问题

一个刚创建的用户testerA,admin用户重置testerA用户密码。对于首次登录的testerA用户来说是无需进行密码修改,可以正常登录

重现方法

image

预期行为

首次登录强制改密码(密码不能和初始密码一致)

版本

  • 提供用户管理的具体版本号
  • 是否是企业版问题?

如果是 SaaS 页面问题,请提供使用的操作系统和浏览器信息

  • OS: [e.g. iOS]
  • Browser [e.g. chrome, safari]
  • Version [e.g. 22]

额外信息

任何你觉得有助于问题解决的内容

@neronkl
Copy link
Contributor Author

neronkl commented Mar 29, 2023

and profile.password_update_time is None

raise error_codes.SHOULD_CHANGE_INITIAL_PASSWORD.format(

@Canway-shiisa Canway-shiisa self-assigned this Mar 31, 2023
@Canway-shiisa Canway-shiisa added this to the Y2023M14 milestone Apr 3, 2023
@Shutulee Shutulee self-assigned this Apr 3, 2023
@Canway-shiisa Canway-shiisa modified the milestones: Y2023M14, Y2023M15 Apr 10, 2023
@Shutulee
Copy link
Collaborator

首次登录强制修改密码的逻辑主要用来规避初始密码 / 默认密码泄漏的风险。
管理员「批量重置密码」功能上线前,暂可不处理(低优)。但原则上,首次登录强制修改密码应该是必须的。
(后续迭代:被管理员批量重置过密码后的用户,也应在首次登录时强制修改密码。)
——————————————————
管理员重置密码功能待确认:重置之后是否会发短信/邮箱通知?

@Canway-shiisa Canway-shiisa removed this from the Y2023M15 milestone Apr 18, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants