As per title:
* user logs in with OpenID, which (in many cases) sets username and email address
* user edits their account to change their "local" password
* user logs out
User is now able to login in using their newly created "local" password.
Ideally, openid-created accounts would not be able to edit their local password.
Comments
Comment #1
walkah commentedThis is likely better as an option ... and one of the things I want to look more closely at in the future. However, disabling user/password logging in does have some side effects like making it unable to recover your account if your OpenID goes away, etc. An OpenID is not an account..
Switching this to a feature.
Comment #2
moshe weitzman commentedYeah, I think closing the door on the local account can be a bad idea. I know that the presence of this field can be confusing though.
Comment #3
panchoWon't fix in D6, let's implement it in D7...
Comment #4
mchelenYes it should be optional, for some cases it would not be advisable, in others the benefits can outweigh the problems.
Comment #5
heine commentedI don't understand why this is an issue.
Comment #6
heine commentedSummary: An OpenID is not an account.