Logged out after password change

Bug #868411 reported by Tom Hoffman
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
SchoolTool
Fix Released
High
Douglas Cerna

Bug Description

It is strange that after entering your password two times, you are logged out, and have to type that same password again.

I think this is becauses credentials are stored in user's session, but why is that needed, don't know...

Revision history for this message
Douglas Cerna (replaceafill) wrote :

According to Tom's magic 8 ball:

"Logging them out with a warning seems like the safer route."

so I the user still will be logged out but I added the message:

"Password changed successfully. Next, you will be required to authenticate with your new credentials"

Changed in schooltool:
status: Incomplete → Fix Committed
Revision history for this message
Tom Hoffman (tom-hoffman) wrote :

The problem with this is that the user's next step isn't clear.

Revision history for this message
Gediminas Paulauskas (menesis) wrote :

Changing password was fixed (LP: #250556)

But navigation after changing password for yourself (the need to log in again, and the dialog), or for someone else (password changed successfully notice, then have to click cancel) is still awkward.

summary: - possible password issues
+ Logged out after password change
Changed in schooltool:
status: Fix Committed → New
description: updated
security vulnerability: yes → no
visibility: private → public
Revision history for this message
Tom Hoffman (tom-hoffman) wrote :

I don't have a problem with users having to log back in. Manager shouldn't have to cancel though. A confirmation dialog and sending them back to the user page would be good.

Changed in schooltool:
importance: High → Low
importance: Low → Undecided
importance: Undecided → High
status: New → Triaged
Revision history for this message
Douglas Cerna (replaceafill) wrote :

Now when users change their own passwords they get the dialog with the "Password changed successfully" message and then they're redirected to their index view without needing to log in again. Same for admins changing somebody else's password.

Changed in schooltool:
status: Triaged → Fix Committed
Changed in schooltool:
milestone: none → 2.0.2
Changed in schooltool:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.