RocketChat / RocketChat/Rocket.Chat
Change password should be ex-oauth user friendly
Open
Nobody has claimed this yet.
security
- Dominant language
- TypeScript
- Stars
- 46.1k
- Forks
- 13.9k
- Avg merge
- 3d 3h
- Merged PRs (30d)
- 130
Description
For Oauth users wanting to switch to regular password login, they are in a catch 22.
They need the old password to set a new one. (Don't remove this requirement ...security 101).
Want to back this issue? Post a bounty on it! We accept bounties via Bountysource.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are named in the issue. Clarify the intended password-change flow for OAuth users while retaining the old-password security requirement, then verify that the resulting flow supports switching to regular password login.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- authentication
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100