? ?
avatar ReLater
ReLater
11 Jan 2019

Steps to reproduce the issue

  • Go to Users > Options (administrator/index.php?option=com_config&view=component&component=com_users)
  • Check the default settings for "Password Options".

These values are faaaar away from being secure. J4 gives us the possibility to define a little bit more secure default settings for newly created accounts.

Suggestions please if accepted.

avatar ReLater ReLater - open - 11 Jan 2019
avatar joomla-cms-bot joomla-cms-bot - change - 11 Jan 2019
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 11 Jan 2019
avatar joomla-cms-bot joomla-cms-bot - change - 11 Jan 2019
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 11 Jan 2019
avatar ReLater ReLater - change - 11 Jan 2019
The description was changed
avatar ReLater ReLater - edited - 11 Jan 2019
avatar ReLater ReLater - change - 11 Jan 2019
The description was changed
avatar ReLater ReLater - edited - 11 Jan 2019
avatar brianteeman
brianteeman - comment - 11 Jan 2019

IIRC (and I could be wrong) the reason for the current default values was because of how to handle existing users who created passwords before any restrictions were created

avatar ReLater
ReLater - comment - 11 Jan 2019

Only new users or users with a flag "Require Password Reset" will be forced to respect theses settings. Existing passwords are not affected. I haven't tested that with J4 but in J3 it's like that.

BTW: If an administrator creates a new user account (back-end) without entering a password these settings are also ignored (hard coded length of new random password). Maybe that should be also lengthened a bit(?)

avatar brianteeman
brianteeman - comment - 11 Jan 2019

If the settings are ignored then that is a bug

avatar ReLater
ReLater - comment - 12 Jan 2019

If an administrator creates a new user account (back-end) without entering a password these settings are also ignored

Just to confirm this behavior in J4:

avatar ReLater ReLater - change - 15 Feb 2019
Status New Closed
Closed_Date 0000-00-00 00:00:00 2019-02-15 21:17:36
Closed_By ReLater
avatar ReLater ReLater - close - 15 Feb 2019

Add a Comment

Login with GitHub to post a comment