Bug 51404 - Self Service: Expired passwords need to be handled better - "Protect account"
Summary: Self Service: Expired passwords need to be handled better - "Protect account"
Status: NEW
Alias: None
Product: UCS
Classification: Unclassified
Component: Self Service
Version: UCS 4.4
Hardware: Other Windows NT
: P5 normal
Target Milestone: ---
Assignee: UMC maintainers
QA Contact: UMC maintainers
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-06-02 17:10 CEST by Michael Grandjean
Modified: 2024-11-25 10:56 CET (History)
2 users (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 2: Improvement: Would be a product improvement
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID: 05017
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Grandjean univentionstaff 2020-06-02 17:10:16 CEST
UCS: 4.4-4 errata617

Scenario: I use a simple password policy, e.g. minimum length is 8 characters. I have a user whose password expired. This is quite common for new users, when the option "change password at next login" is checked. This user tries to use the Self Service to change their password.

Expected behaviour: The Self Service dialog for "Protect account" tells me that my password expired. It then offers to change my password and tells me the requirements (e.g. at least 8 characters).

Observed behaviour: The Self Service dialog for "Protect account" does not tell me that my password expired. Instead it says:
"An error occurred
You are not authorized to perform this action.

Server error message:

Either username or password is incorrect or you are not allowed to use this service."


The user's primary group is listed in "umc/self-service/passwordreset/whitelist/groups".