Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-132641

Toggle for enabling and disabling Password Verification for user account changes

    Details

      Description

      Issue
      Liferay doesn't have a toggle for enabling and disabling Password Verification for user account changes. It is enabled by default starting with LPS-112726. Although the security concerns are completely valid, this use case doesn't take SSO usage into consideration. When using SSOs, the assumption is that the user will never need to manage, know, or even have a Liferay application password. This property to enforce Password Verification for user account changes (on email address or screen names) should be allowed to be disabled.

      Steps to Reproduce

      1. Start Liferay
      2. Sign in to Liferay
      3. Create a new user
      4. Sign in as the new user
      5. Edit the user's account settings
      6. Change the email address or screen name
      7. Click Save

      Actual Behavior
      Due to LPS-112726, we get a prompt that a password is required.

      Expected Behavior
      LPS-112726 needs to consider environments that use an SSO where a Liferay password is not maintained or used. I would expect that there is a toggle or property to disable this functionality.

      Reproduced in

      • 7.3.x-private Commit: 8216c588e3d7d5ffb0819ecc815f1fd53207c8c7
      • Master-private Commit: ad820095bf57409341e820a33604db87e19c8451

        Attachments

          Activity

            People

            Assignee:
            patricia.perez Patricia Perez
            Reporter:
            christopher.kian Christopher Kian
            Participants of an Issue:
            Recent user:
            Michael Bowerman
            Engineering Assignee:
            Christopher Kian
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Days since last comment:
              16 weeks, 6 days ago

                Packages

                Version Package
                7.3.X
                7.4.1 CE GA2 DXP 7,4
                Master