Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NAS-131826 / 25.04 / Enforce old password for non-FULL_ADMIN users #14701

Merged
merged 2 commits into from
Oct 17, 2024

Conversation

yocalebo
Copy link
Contributor

@yocalebo yocalebo commented Oct 17, 2024

When a non-full_admin user is authenticated to our API, that user must provide (and it be validated correctly) the current password if they so choose to change their password. This is also required by STIG SRG-OS-000373-GPOS-00158. A test has been added to validate this functionality.

Passing tests are here

@bugclerk
Copy link
Contributor

@bugclerk bugclerk changed the title Enforce old password for non-FULL_ADMIN users NAS-131826 / 25.04 / Enforce old password for non-FULL_ADMIN users Oct 17, 2024
@bugclerk
Copy link
Contributor

This PR has been merged and conversations have been locked.
If you would like to discuss more about this issue please use our forums or raise a Jira ticket.

@truenas truenas locked as resolved and limited conversation to collaborators Oct 17, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants