Skip to content

Make password reset better #11

@AbstractBeliefs

Description

@AbstractBeliefs

Once #7 lands, when a password is reset:

  1. A new password goes out in the clear
  2. There is no obligation to change this password

We should at least fix 2, that is to say, force users to pick a new password as soon as they connect with the password we sent to them for reset purposes.

Ideally we should also make it that accounts with an open password reset are further secured if they are not updated within 24h or such, so that passwords sitting in peoples inboxes aren't valid in perpetuity.

This may be helpful to explore the options available: https://wiki.tardis.ed.ac.uk/wiki/Browse_LDAP

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions