Jump to content

Account Settings > Security and Privacy

Go to solution Solved by Johno2518,

Recommended Posts

NOTE: This is only visible for existing users that then login with the OAUTH IDP (linking the IPS account with the IDP account).

A new user logging in does not see the highlighted section, they just see the Sign In button for re-authentication as shown below. Presumably this requires clearing the password (AdminCP shows a "Set Password" button for a new user) but I don't see any obvious way of doing so via AdminCP.

Could contain: Text, Page

Link to comment
Share on other sites

1 minute ago, Johno2518 said:

@Marc is there a way to clear the password of user accounts in the AdminCP? I haven't seen anything in there.

Could contain: Text

You can do this via the ACP members, and force a Password Reset. Button next to the green one.

Link to comment
Share on other sites

@Marc thanks for confirming! The problem here is converting from a local IPS account to using an IDP only which makes the password irrelevant for members. I can understand for admins having both is a must in case of configuration issues (or just having local account only for break glass scenarios).

I assume having the ability to "Clear Passwords" would be a feature request.

In terms of doing that now, I assume the only way is to run a DB query. Are there any gotcha's I need to be aware of or is it simply a case of checking a new user account with existing accounts and see what the difference is (i.e. is it just a cleared password field)?

Link to comment
Share on other sites

Without having tested doing this, there is no way I am able to say if it will cause any issues unfortunately. Simpy as its not something we have tested doing. All I can advise is testing this with a copy of your site, or at least being in a position to restore back if you test it on your live site

Link to comment
Share on other sites

  • Solution

Not a problem, I got it sorted.

I created a test member account setting it with a password. Setting the "members_pass_hash" and "members_pass_salt" fields to null for the test member in the core_members table resulted in the AdminCP showing "Set Password" as the option. The Security and Privacy section now requests Sign In using the IDP to continue.

Everything now as if the user had joined using the IDP login.

Link to comment
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Create New...