Block password reset if "Force SAML login" is enabled

Created on 16 November 2021, about 3 years ago
Updated 11 September 2024, 4 months ago

When "Force SAML Login" is enabled, the login form will not be used. However if user goes directly to /user/password to generate a one time login link, it is possible. I think we should block this form too (but keep the /user/reset route so that you can still use the OTL link (e.g. generated via drush) but normal users can't.

✨ Feature request
Status

Fixed

Version

4.0

Component

Code

Created by

πŸ‡«πŸ‡·France jcisio Paris

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024