- π³πΏNew Zealand quietone
@japerry, thank for bring this issue up.
This was a bugsmash daily target a few days ago. It was discussed by lendude, larowlan and myself. lendude pointed out that "changing this would really mess with our maintainer login policy where our maintainer users are not allowed to have a password at all and you can only login via drush uli". I checked what OWASP had to say on the subject and it does not disagree with this practice. In the end we all agree that this is working as designed.
Later, I tested the link and found that the flow was a bit confusing and that matches what is mentioned in #4. Then, I looked for duplicate issues and found β¨ Include fields for resetting password on the one-time password reset page Active . That issue has more discussion, and has had a usability review. It is also a feature request while this is a bug. I checked the definition of bug β and this does not fit. So, I am changing to a feature request like the other issue.
Since these are so similar, I am closing this as a duplicate and moving credit.
- πΊπΈUnited States brad.bulger
Closed but never solved, very nice. Maybe it doesn't fit "the definition of bug" (lol) but it sure seems like a problem to people who run into it. Another forever-patch.