Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

When a user changes a password (or resets password), inform user that token_auth will change #9833

Closed
alexplusde opened this Issue Feb 23, 2016 · 2 comments

Comments

Projects
None yet
2 participants
@alexplusde
Copy link

alexplusde commented Feb 23, 2016

Piwik stopped archiving a few days ago and I didn't know why until i found this thread:

https://forum.piwik.org/t/web-cron-archiving-error/15971
"woops. It appears I changed my password recently, thereby changing the token_auth. I'll go cry in shame somewhere."

Advanced users may know that a new password also causes a new token. But people new to piwik should be told about it. For example via password changing e-mail or after the password changing dialogue.

@tsteur

This comment has been minimized.

Copy link
Member

tsteur commented Feb 24, 2016

Very good point. We definitely need to mention this as it is not "normal" that token changes when you change password. It will break all kinda API access and will cause other apps and integrations etc to fail.

Also related to this is : #6559 which we will hopefully tackle in Piwik 3. It's very much needed.

@alexplusde

This comment has been minimized.

Copy link
Author

alexplusde commented Feb 27, 2016

It looks like you'll be informed if you change the password in piwik backend but not if you use the password reset option.

sgiehl added a commit that referenced this issue Mar 6, 2016

refs #9833 - Improve password reset confirmation mail text to inform …
…user that token_auth will change aswell

@tsteur tsteur closed this Mar 6, 2016

@tsteur tsteur added this to the 2.16.1 milestone Mar 6, 2016

@mattab mattab changed the title inform user that a new password will change API-token and may break webcrons etc. When a user changes a password (or resets password), inform user that token_auth will change Mar 31, 2016

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.