Skip to content

No validation done when user resets a password #12580

@kiranchavala

Description

@kiranchavala

The required feature described as a wish

Steps to reproduce the issue

  1. Enable the global setting "user.password.reset.enabled"

  2. Click on forgot password option from the UI

Image Image Image Image
  1. User provides the same password, Cloudstack doesn't validate the password and sets the same password for the user

Expected behaviour

Cloudstack should validate if the same password is used for reset password, this can prevent security related issues

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions