Your achievements

Level 1

0% to

Level 2

Tip /
Sign in

Sign in to Community

to gain points, level up, and earn exciting badges like the new
Bedrock Mission!

Learn more

View all

Sign in to view all badges

Improvement of change password UI/UX

Avatar

Level 1

13-09-2021

Request for Feature Enhancement (RFE) Summary:

Want to Improve input items and error message of chenge password.

Use-case:
  • /system/console/configMgr/org.apache.jackrabbit.oak.security.user.UserConfigurationImpl
    Enable "Password On First Login"
  • /system/console/configMgr/org.apache.jackrabbit.oak.spi.security.user.action.DefaultAuthorizableActionProvider
    Set "Configure PasswordValidationAction: Password Constraint"
  • For enhanced security, I want to lock my account after multiple authentication failures.
    For this purpose, we override "AuthenticationHandler.authenticationFailed" to achieve the lock function.
Current/Experienced Behavior:
  • After you have been authenticated with your ID and password, the password change screen will appear.
    You will need to enter the password again on the password change screen.
  • The message on new password validation error is "Your password has expired".
  • "AuthenticationHandler.authenticationFailed" is called with new password validation error.
    Therefore, it will be account locked due to a password validation error.
Improved/Expected Behavior:
  • Message at the time of password validation error is "Password violates password constraintd".
  • Do not call "AuthenticationHandler.authenticationFailed" with new password validation error.
    or to eliminate the current password when chenge password.
Environment Details (AEM version/service pack, any other specifics if applicable): AEM6.5
Customer-name/Organization name:  
Screenshot (if applicable): image.png
Code package (if applicable):  
4 Comments

Avatar

Employee Advisor

20-09-2021

Hello @hsim3 

I have tried the behavior on OOTB without customization of "AuthenticationHandler.authenticationFailed" and everything works as expected

As the override of "AuthenticationHandler.authenticationFailed" is done at the project level via customization, this request will have to be performed at the project level as well unfortunately

 

Thanks

Status changed to: Needs Info

Avatar

Level 1

23-09-2021

Hello clatimier

Thank you for checking.

What is expected of the message displayed when a password verification error occurs?

 

 

 

Avatar

Employee Advisor

19-10-2021

Hi @hsim3 

When you will connect the first time, you will have the "Your password has expired" message

Then after providing a new one, you will see a "Your password has been changed successfully" message

 

clatimier_0-1634628299673.png

If you connect with incorrect credentials, you will see

clatimier_1-1634628371644.png

 

Does that answer your question? As I'm unsure of what information you're looking for.

Status changed to: Needs Info

Avatar

Level 1

20-10-2021

Hello clatimier

 

The message on new password validation error is "Your password has expired".
Could you check this?
1.PNG