U4-10819 - Password change does not update last password change date in database

Created by Kraftwerk 10 Jan 2018, 15:02:20 Updated by Sebastiaan Janssen 14 Jul 2018, 16:51:36

Tags: Up For Grabs PR

Duplicates: U4-10849

Subtask of: U4-11011

If you change the password in the UI, the database field "lastPasswordChangeDate" in table "UmbracoUser" does not get updated. Pretty bad if you have custom code relying on that for password expiry.

Works in version 7.6.6 but no longer in latest 7.7.8

1 Attachments

Comments

Sebastiaan Janssen 10 Jan 2018, 15:38:39

Sure.. but password expiry is not a good idea :-)

https://nakedsecurity.sophos.com/2016/08/18/nists-new-password-rules-what-you-need-to-know/

Would be great if you could send us a PR to fix the issue! :)


Kraftwerk 10 Jan 2018, 17:23:24

About the password expiry - sometimes you have to see it from a different perspective - if the security department of your customer demands it, you can no longer argue about it :)

Sorry for not creating that bug as you would have wished. What do you exactly mean by sending PR?


Sebastiaan Janssen 10 Jan 2018, 21:54:32

Your customer's security department needs a bit of education then! ;-)

PR as in: Pull Request (sorry for the abbreviation).


Sam 22 Feb 2018, 04:57:01

Here is a PR that should fix the issue: https://github.com/umbraco/Umbraco-CMS/pull/2463


Priority: Normal

Type: Bug

State: Duplicate

Assignee:

Difficulty: Normal

Category: UI

Backwards Compatible: True

Fix Submitted:

Affected versions: 7.7.8

Due in version:

Sprint:

Story Points:

Cycle: