Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Feature Requests
  3. Password Reset should be an option for logged-in users too

Password Reset should be an option for logged-in users too

Scheduled Pinned Locked Moved Solved Feature Requests
24 Posts 7 Posters 3.3k Views 7 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • nebulonN nebulon

      I am not sure what this really is about, but a user can edit his/her password through the Cloudron dashboard, but of course like with other services at least I am aware of, you have to provide the old password when setting a new one through a login session.

      Password resets are instead verified by the email with the reset link.

      I also don't think it is correct to allow password change without some kind of additional verification means otherwise if a valid access token leaks for a user, anyone with that token can change the password.

      jdaviescoatesJ Offline
      jdaviescoatesJ Offline
      jdaviescoates
      wrote on last edited by jdaviescoates
      #12

      @nebulon I think the request is basically about adding an "email me a password reset link" button to the existing page where users can change their password (if they know their PW), right @marcusquinn ?

      I use Cloudron with Gandi & Hetzner

      marcusquinnM 1 Reply Last reply
      1
      • jdaviescoatesJ jdaviescoates

        @nebulon I think the request is basically about adding an "email me a password reset link" button to the existing page where users can change their password (if they know their PW), right @marcusquinn ?

        marcusquinnM Offline
        marcusquinnM Offline
        marcusquinn
        wrote on last edited by marcusquinn
        #13

        @jdaviescoates Exactly that. There's no issue with security because it's no different to getting the link when logged out.

        It is a usability issue, in that you have to first logout to trigger the email reset link.

        It would also be good if it is always available on a memorable link too, like: https://my.example.com/password-reset as it's easy to then type out, in response to this question that seems to come up a couple of times a month among 60 users.

        Web Design https://www.evergreen.je
        Development https://brandlight.org
        Life https://marcusquinn.com

        nebulonN 1 Reply Last reply
        1
        • marcusquinnM marcusquinn

          @jdaviescoates Exactly that. There's no issue with security because it's no different to getting the link when logged out.

          It is a usability issue, in that you have to first logout to trigger the email reset link.

          It would also be good if it is always available on a memorable link too, like: https://my.example.com/password-reset as it's easy to then type out, in response to this question that seems to come up a couple of times a month among 60 users.

          nebulonN Offline
          nebulonN Offline
          nebulon
          Staff
          wrote on last edited by
          #14

          @marcusquinn I see github and the likes also show a password reset link in the profile. We can do this as well, as it essentially just prefills the regular password reset form with the email address.

          There are two blocking issues, we need to fix first though:

          1. Currently in a login session you could just change the email address right there and then trigger the password reset (this is already a bit of an issue so we will fix this anyways to require the password on email change)
          2. Fix the password reset page to allow prefilling and directly jump into that form unlike now from the login page.
          marcusquinnM 1 Reply Last reply
          2
          • nebulonN nebulon

            @marcusquinn I see github and the likes also show a password reset link in the profile. We can do this as well, as it essentially just prefills the regular password reset form with the email address.

            There are two blocking issues, we need to fix first though:

            1. Currently in a login session you could just change the email address right there and then trigger the password reset (this is already a bit of an issue so we will fix this anyways to require the password on email change)
            2. Fix the password reset page to allow prefilling and directly jump into that form unlike now from the login page.
            marcusquinnM Offline
            marcusquinnM Offline
            marcusquinn
            wrote on last edited by
            #15

            @nebulon Sounds good - be happy with that!

            Web Design https://www.evergreen.je
            Development https://brandlight.org
            Life https://marcusquinn.com

            nebulonN 1 Reply Last reply
            0
            • marcusquinnM marcusquinn

              @nebulon Sounds good - be happy with that!

              nebulonN Offline
              nebulonN Offline
              nebulon
              Staff
              wrote on last edited by
              #16

              @marcusquinn this has been implemented now and will be part of the next release.

              marcusquinnM 2 Replies Last reply
              2
              • nebulonN nebulon

                @marcusquinn this has been implemented now and will be part of the next release.

                marcusquinnM Offline
                marcusquinnM Offline
                marcusquinn
                wrote on last edited by
                #17

                @nebulon Magic - thank you kindly!

                Often I end up doing support over the phone or SMS without web access, so hoping this will make it easier to verbalise instructions without needing to copy/paste links.

                Web Design https://www.evergreen.je
                Development https://brandlight.org
                Life https://marcusquinn.com

                1 Reply Last reply
                2
                • nebulonN nebulon

                  @marcusquinn this has been implemented now and will be part of the next release.

                  marcusquinnM Offline
                  marcusquinnM Offline
                  marcusquinn
                  wrote on last edited by
                  #18

                  @nebulon Can I get an ETA on this, and what the URL will be please? (ideally something memorable, like my.example.com/password-reset)

                  Web Design https://www.evergreen.je
                  Development https://brandlight.org
                  Life https://marcusquinn.com

                  nebulonN 1 Reply Last reply
                  0
                  • marcusquinnM marcusquinn

                    @nebulon Can I get an ETA on this, and what the URL will be please? (ideally something memorable, like my.example.com/password-reset)

                    nebulonN Offline
                    nebulonN Offline
                    nebulon
                    Staff
                    wrote on last edited by
                    #19

                    @marcusquinn So what has been implemented is a way to reset the password on behalf of the user as an admin. If I understand you correctly, then you also want a direct link for the user to reset the password on his/her own?

                    This does already exist though: https://my.example.com/login.html?passwordReset
                    Would that work for you?

                    jdaviescoatesJ marcusquinnM 2 Replies Last reply
                    2
                    • nebulonN nebulon

                      @marcusquinn So what has been implemented is a way to reset the password on behalf of the user as an admin. If I understand you correctly, then you also want a direct link for the user to reset the password on his/her own?

                      This does already exist though: https://my.example.com/login.html?passwordReset
                      Would that work for you?

                      jdaviescoatesJ Offline
                      jdaviescoatesJ Offline
                      jdaviescoates
                      wrote on last edited by
                      #20

                      @nebulon said in Password Reset should be an option for logged-in users too:

                      @marcusquinn So what has been implemented is a way to reset the password on behalf of the user as an admin. If I understand you correctly, then you also want a direct link for the user to reset the password on his/her own?

                      That was my understanding of what @marcusquinn wanted too - for already existing logged in users to be able to reset their own passwords...

                      This does already exist though: https://my.example.com/login.html?passwordReset
                      Would that work for you?

                      Heh, I think that is exactly what @marcusquinn was after!

                      That should be added to the docs somewhere!

                      I use Cloudron with Gandi & Hetzner

                      1 Reply Last reply
                      0
                      • nebulonN nebulon

                        @marcusquinn So what has been implemented is a way to reset the password on behalf of the user as an admin. If I understand you correctly, then you also want a direct link for the user to reset the password on his/her own?

                        This does already exist though: https://my.example.com/login.html?passwordReset
                        Would that work for you?

                        marcusquinnM Offline
                        marcusquinnM Offline
                        marcusquinn
                        wrote on last edited by
                        #21

                        @nebulon Kinda not so memorable. I can't be the only Sys Admin that gets requests day and night that you have to answer by phone and memory? Can we have a URL rewrite for /password-reset?

                        Web Design https://www.evergreen.je
                        Development https://brandlight.org
                        Life https://marcusquinn.com

                        robiR 1 Reply Last reply
                        1
                        • marcusquinnM marcusquinn

                          @nebulon Kinda not so memorable. I can't be the only Sys Admin that gets requests day and night that you have to answer by phone and memory? Can we have a URL rewrite for /password-reset?

                          robiR Offline
                          robiR Offline
                          robi
                          wrote on last edited by
                          #22

                          @marcusquinn said in Password Reset should be an option for logged-in users too:

                          @nebulon Kinda not so memorable. I can't be the only Sys Admin that gets requests day and night that you have to answer by phone and memory? Can we have a URL rewrite for /password-reset?

                          why not create a short URL that you'll remember?

                          Conscious tech

                          marcusquinnM 1 Reply Last reply
                          2
                          • robiR robi

                            @marcusquinn said in Password Reset should be an option for logged-in users too:

                            @nebulon Kinda not so memorable. I can't be the only Sys Admin that gets requests day and night that you have to answer by phone and memory? Can we have a URL rewrite for /password-reset?

                            why not create a short URL that you'll remember?

                            marcusquinnM Offline
                            marcusquinnM Offline
                            marcusquinn
                            wrote on last edited by
                            #23

                            @robi Why not have as I've suggested? 🤷 This suggestion has a duplicate time cost and no benefit to any other CLoudron users.

                            It's considered feedback and a simple recommendation from trying to manage 50+ users of various computer literacy. The suggestion is good, and will help anyone else managing many variable Cloudron Users. No need for the debate time is starting to exceed the implementation time.

                            Web Design https://www.evergreen.je
                            Development https://brandlight.org
                            Life https://marcusquinn.com

                            robiR 1 Reply Last reply
                            1
                            • marcusquinnM marcusquinn

                              @robi Why not have as I've suggested? 🤷 This suggestion has a duplicate time cost and no benefit to any other CLoudron users.

                              It's considered feedback and a simple recommendation from trying to manage 50+ users of various computer literacy. The suggestion is good, and will help anyone else managing many variable Cloudron Users. No need for the debate time is starting to exceed the implementation time.

                              robiR Offline
                              robiR Offline
                              robi
                              wrote on last edited by
                              #24

                              @marcusquinn because it already exists 🙂

                              Conscious tech

                              1 Reply Last reply
                              0
                              Reply
                              • Reply as topic
                              Log in to reply
                              • Oldest to Newest
                              • Newest to Oldest
                              • Most Votes


                                • Login

                                • Don't have an account? Register

                                • Login or register to search.
                                • First post
                                  Last post
                                0
                                • Categories
                                • Recent
                                • Tags
                                • Popular
                                • Bookmarks
                                • Search