Last modified: 2014-03-01 12:43:19 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T56997, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 54997 - Add Password Expiration functionality
Add Password Expiration functionality
Status: RESOLVED FIXED
Product: MediaWiki
Classification: Unclassified
General/Unknown (Other open bugs)
1.22.0
All All
: Normal enhancement (vote)
: ---
Assigned To: Chris Steipp
:
Depends on: 61692
Blocks:
  Show dependency treegraph
 
Reported: 2013-10-05 01:38 UTC by Chris Steipp
Modified: 2014-03-01 12:43 UTC (History)
8 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Chris Steipp 2013-10-05 01:38:17 UTC
In the event that the site owner needs the users to change their password for some reason, it would be nice for MediaWiki to have the concept of password expiration.

Typically, I've seen this implemented that a date attribute can be stored on the User, and then a configurable number of days before or after that date, the user gets a "soft" password reset on login-- they are asked to change their password, but they are still logged in and can skip the process for now. After the "soft" phase, the user gets a "hard" reset, and cannot login without changing their password.

After the user resets their password, we could probably have a flag to automatically set the next expiration date, for users that need to comply with password-reset schedules.

The WMF currently has a hack in place on their sites to do a "hard" reset for a set of users, so having this feature in core would decrease our tech-debt, as well as providing a better product for other users of MediaWiki.
Comment 1 Chris Steipp 2013-10-05 04:30:37 UTC
Oh, and as Daniel mentioned on https://bugzilla.wikimedia.org/show_bug.cgi?id=28419#c82, we should add a way to for a custom message when we trigger big resets.
Comment 2 Liangent 2013-10-07 16:09:17 UTC
(In reply to comment #0)
> the user gets a "hard" reset, and cannot login without
> changing their password.

maybe add "to a new, different password", or even "to a password that has never been used for this account".
Comment 3 Gerrit Notification Bot 2013-10-29 00:19:55 UTC
Change 92037 had a related patch set uploaded by CSteipp:
Password Expiration (WIP)

https://gerrit.wikimedia.org/r/92037
Comment 4 Gerrit Notification Bot 2014-02-21 20:28:32 UTC
Change 92037 merged by jenkins-bot:
Password Expiration

https://gerrit.wikimedia.org/r/92037
Comment 5 db [inactive,noenotif] 2014-03-01 12:43:19 UTC
Status Merged

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links