Bug 51404 - Self Service: Expired passwords need to be handled better - "Protect account"
Self Service: Expired passwords need to be handled better - "Protect account"
Status: NEW
Product: UCS
Classification: Unclassified
Component: Self Service
UCS 4.4
Other Windows NT
: P5 normal (vote)
: ---
Assigned To: UMC maintainers
UMC maintainers
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-06-02 17:10 CEST by Michael Grandjean
Modified: 2020-09-07 16:06 CEST (History)
1 user (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Grandjean univentionstaff 2020-06-02 17:10:16 CEST
UCS: 4.4-4 errata617

Scenario: I use a simple password policy, e.g. minimum length is 8 characters. I have a user whose password expired. This is quite common for new users, when the option "change password at next login" is checked. This user tries to use the Self Service to change their password.

Expected behaviour: The Self Service dialog for "Protect account" tells me that my password expired. It then offers to change my password and tells me the requirements (e.g. at least 8 characters).

Observed behaviour: The Self Service dialog for "Protect account" does not tell me that my password expired. Instead it says:
"An error occurred
You are not authorized to perform this action.

Server error message:

Either username or password is incorrect or you are not allowed to use this service."


The user's primary group is listed in "umc/self-service/passwordreset/whitelist/groups".