-
Notifications
You must be signed in to change notification settings - Fork 233
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Change password without the old password #41
Comments
Thanks! Do you want to do this as a user (i.e. let the user do this on their own) or as an administrator? For the first case, the decision to require the old password as well has been intentional. But perhaps there might be some use cases where this is not required. |
Hi ocram, Yes, I want to do this as a user. I've seen the function updatePassword inside Auth.php :) |
Will be available shortly, using a small wrapper around |
I wasn't sure if this would be secure? but isn't password update a sensitive access? What if someone use rememberme by mistake on a public computer and somebody change the password without needing to input the old password? |
But as an admin it sound logical. |
@fdiengdoh You're absolutely right. That's why the current method for changing the password still requires the old password to be entered. With the new method added, the old one will still be the recommended one and the default. |
Hi,
Is there any way to update the user password without the old password?
The text was updated successfully, but these errors were encountered: