policy to prevent user doing anything until he changes expired password
iva2k - June 14, 2009 - 06:37
| Project: | Password policy |
| Version: | 6.x-1.x-dev |
| Component: | Code |
| Category: | feature request |
| Priority: | normal |
| Assigned: | Unassigned |
| Status: | active |
Jump to:
Description
Also, single-login links should automatically expire the password upon first login, lock user into password change page until he/she successfully changes it. Not doing so opens so many ways to get locked out of a newly created account... that is a very bad first impression that turns our first-time site users away. We need first time users to stay!

#1
OT: Oh boy, I got a long list of issues submitted in today for password_policy...
That does not make me not like the module. It is a first-class addition to drupal. Having all these new features will make it so sweet and right that nobody would be able to live without it.