|
Users could not find the Change password fields |
Needs work |
Normal |
Bug report |
main |
user.module |
|
14 years 8 months |
67.456 |
|
Replace confirm password element with a new element that allows toggling to view the typed password |
Needs work |
Normal |
Task |
main |
forms system |
|
11 years 10 months |
52.595 |
|
Password suggestions are hidden from screenreaders |
Needs work |
Normal |
Bug report |
main |
user system |
|
4 years 3 weeks |
43.678 |
|
Include fields for resetting password on the one-time password reset page |
Active |
Major |
Feature request |
main |
user system |
|
19 years 9 months |
43.482 |
|
Allow password on registration without disabling e-mail verification |
Needs work |
Normal |
Feature request |
main |
user.module |
|
19 years 2 months |
38.605 |
|
Require a (configurable) minimum password length for user accounts |
Active |
Major |
Feature request |
main |
user system |
|
13 years 6 months |
34.036999999999999 |
|
Allow the user edit form to only ask for the current password when necessary (in a followup confirmation step) |
Active |
Normal |
Task |
main |
user system |
|
16 years 7 months |
29.735 |
|
Check for common words in password strength indicators |
Needs work |
Normal |
Task |
main |
user.module |
|
14 years 1 month |
29.010999999999999 |
|
Preserve destination parameter across password reset worklow |
Active |
Normal |
Feature request |
main |
user.module |
|
2 years 11 months |
28.551 |
|
Improve Password Field Arrangement on User Profile Page |
Needs work |
Normal |
Feature request |
main |
other |
|
1 year 1 month |
27.25 |
|
Password length is 128 but error message says it is 255 |
Needs work |
Normal |
Bug report |
main |
user system |
|
5 years 10 months |
26.509 |
|
Don't trim whitespace when setting user password |
Needs work |
Normal |
Bug report |
main |
user.module |
|
13 years 2 months |
26.088999999999999 |
|
Error highlighting and reporting problems for the current password on the user profile form |
Needs work |
Normal |
Bug report |
main |
user.module |
|
11 years 1 month |
26.081 |
|
Allow password reset on account with the username matching another email; prevent registrations that match another account |
Needs work |
Normal |
Bug report |
main |
user.module |
|
14 years 4 months |
25.181 |
|
Add [current-request:*] tokens |
Active |
Normal |
Feature request |
main |
token system |
|
5 years 11 months |
25 |
|
Support passkey and any other login flow that is more than username+password |
Active |
Major |
Feature request |
main |
user.module |
|
1 year 5 months |
19.716 |
|
Multiple errors in PasswordItem::preSave(), leads to data loss if field is translatable |
Needs work |
Normal |
Bug report |
main |
field system |
|
10 years 10 months |
19.532 |
|
Error class is set to wrong password element in accounts form. |
Needs work |
Normal |
Bug report |
main |
user.module |
|
2 years 5 months |
18.718 |
|
Include length in password strength evaluation |
Needs review |
Normal |
Task |
main |
user system |
|
16 years 11 months |
18.421 |
|
Settings.php $databases example improvement |
Needs work |
Minor |
Task |
main |
install system |
|
16 years 2 months |
18.165 |
|
Installer does not pick up password value from settings.php when hash_salt is not pre-populated |
Active |
Normal |
Bug report |
main |
install system |
|
5 years 2 months |
17.857 |
|
Prevent empty passwords being stored |
Needs work |
Normal |
Feature request |
main |
user system |
|
3 weeks 2 days |
16.4 |
|
Provide a standard mechanism to determine whether a user's password can be reset. |
Needs work |
Normal |
Feature request |
main |
user.module |
|
9 years 2 months |
15.5 |
|
AJAX forms should submit to $form['#action'] instead of <current> |
Active |
Major |
Bug report |
main |
ajax system |
|
10 years 10 months |
15.394 |
|
"A client error happened" on Forget password due to malicious request attempt to a Drupal-based website and response is getting cached |
Needs work |
Major |
Bug report |
main |
user system |
|
1 year 10 months |
14.852 |
|
Provide option to disable password recovery by e-mail |
Needs work |
Normal |
Feature request |
main |
user.module |
|
11 years 6 months |
14.314 |
|
Password reset invalid mail notify language |
Needs work |
Normal |
Bug report |
main |
language system |
|
4 years 1 month |
13.878 |
|
Facilitate 2FA+MultiFactor compatibility (2FA/two-factor -> MFA/multi-factor) |
Active |
Major |
Feature request |
main |
user system |
|
8 years 8 months |
13.156 |
|
Split up and change "User name and password" field |
Active |
Normal |
Feature request |
main |
user.module |
|
14 years 10 months |
13 |
|
Clear text submission of password vulnerability |
Postponed (maintainer needs more info) |
Major |
Feature request |
main |
user.module |
|
1 year 6 months |
12.895 |
|
[meta] Update the user-edit pages |
Active |
Normal |
Task |
main |
user.module |
|
4 years 4 months |
12.297 |
|
Only apply ProtectedUserFieldConstraintValidator when authenticated using Cookie AuthenticationProvider |
Needs work |
Normal |
Feature request |
main |
user.module |
|
6 years 9 months |
12.090999999999999 |
|
Allow providing default value for the Password form field type |
Active |
Normal |
Feature request |
main |
forms system |
|
1 year 3 months |
11.5 |
|
Password reset link should immediately detect if the link is expired |
Needs work |
Minor |
Task |
main |
user system |
|
6 years 10 months |
11.198 |
|
Set "Referrer-Policy" header to prevent leaking secret tokens in URLs |
Needs work |
Normal |
Feature request |
main |
base system |
|
7 years 3 months |
10.714 |
|
Use email verification when changing user email addresses |
Needs work |
Major |
Feature request |
main |
user.module |
|
19 years 7 months |
9.761 |
|
Allow attributes to be passed to the password confirm fields |
Needs work |
Normal |
Bug report |
main |
forms system |
|
6 years 7 months |
9.543 |
|
Move the request for current password on email/password change to a modal dialog. |
Active |
Normal |
Feature request |
main |
ajax system |
|
13 years 4 months |
9.5 |
|
[Regression] login link has no destination=drupalSettings.path, so dumps you on the profile |
Needs work |
Normal |
Bug report |
main |
user.module |
|
10 years 6 months |
8.653 |
|
Remove one-time login link from default 'Welcome (no approval required)' email |
Active |
Normal |
Task |
main |
user system |
|
5 years 2 months |
8 |
|
Limit password reset per role |
Postponed (maintainer needs more info) |
Normal |
Feature request |
main |
user.module |
|
16 years 4 months |
8 |
|
[meta] Major issue triage |
Active |
Normal |
Plan |
main |
other |
|
11 years 6 days |
7.795 |
|
Apply formatters and widgets to User base fields 'name' and 'email' |
Needs work |
Major |
Task |
main |
user.module |
|
12 years 4 weeks |
7.713 |
|
[META] Adopt the symfony mailer component |
Needs review |
Normal |
Plan |
main |
mail system |
|
13 years 6 months |
7.649 |
|
Field storage config entities 'indexes' key |
Needs work |
Normal |
Bug report |
main |
field system |
|
15 years 6 months |
7.486 |
|
Protect initial login link against abuse and username leaking |
Needs work |
Normal |
Feature request |
main |
user system |
|
6 years 4 months |
7.018 |
|
trim(): Passing null to parameter #1 of type string is deprecated |
Needs work |
Normal |
Bug report |
main |
user system |
|
3 years 2 months |
6.942 |
|
Requirements and strategy for Core Mailer |
Active |
Normal |
Plan |
main |
base system |
|
9 months 3 weeks |
6.754 |
|
Reduce number of password hashing iterations in all tests to improve test performance |
Needs work |
Normal |
Task |
main |
simpletest.module |
|
12 years 3 months |
6.435 |
|
Security: The "administer users" permission exposes user/1 |
Postponed (maintainer needs more info) |
Normal |
Feature request |
main |
user system |
|
20 years 4 months |
6.348 |