Uploaded image for project: 'Automation Hub'
  1. Automation Hub
  2. AAH-137

Changing your password invalidates session but doesn't redirect to login.

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Normal Normal
    • 1.2
    • None
    • UI
    • None
    • False
    • False
    • Undefined

      When changing your password, after hitting 'save' the 'profile updated' message appears and the password has been successfully changed. This is all good and expected.

      However, if you try to edit your password again, when hitting 'save' the 'profile updated' message doesn't appear, and the change doesn't take - if you refresh the page the most recently set password doesn't work, only the first change.

      Steps to reproduce:
      1. click on your username and hit 'my profile'
      2. hit 'edit'
      3. change your password and hit 'save'

      At this point, my hypothesis is that your session becomes invalid, because it's authenticated according to the old password. As a result, further attempts to change your password won't succeed.

      4. hit 'edit'
      5. change your password and hit 'save'
      6. refresh and try to log in. You should only be able to use the password set in step 3, not the password set in step 5.

      Ideally the page would re-authenticate you with the new password when you change your password. Alternatively, it'd be fine to kick you to the login screen, and make you log in a second time.

            znemecko Zita Nemeckova
            hhummel@redhat.com Henderson Hummel (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated: