<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Password Reset should be an option for logged-in users too]]></title><description><![CDATA[<p dir="auto">Often a user will forget or get confused over passwords.</p>
<p dir="auto">My current instructions are that they need to go to <a href="http://my.example.com" target="_blank" rel="noopener noreferrer nofollow ugc">my.example.com</a>, logout and then do a password reset.</p>
<p dir="auto">Be better if there was a link to trigger the reset email link from already still being logged in too.</p>
]]></description><link>https://forum.cloudron.io/topic/5583/password-reset-should-be-an-option-for-logged-in-users-too</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 23:48:56 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/5583.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 27 Aug 2021 15:11:20 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Sat, 16 Oct 2021 17:36:45 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> because it already exists <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /></p>
]]></description><link>https://forum.cloudron.io/post/37864</link><guid isPermaLink="true">https://forum.cloudron.io/post/37864</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Sat, 16 Oct 2021 17:36:45 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Sat, 16 Oct 2021 10:37:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/robi" aria-label="Profile: robi">@<bdi>robi</bdi></a> Why not have as I've suggested? <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--shrug" style="height:23px;width:auto;vertical-align:middle" title=":shrug:" alt="🤷" /> This suggestion has a duplicate time cost and no benefit to any other CLoudron users.</p>
<p dir="auto">It's considered feedback and a simple recommendation from trying to manage 50+ users of various computer literacy. The suggestion is good, and will help anyone else managing many variable Cloudron Users. No need for the debate time is starting to exceed the implementation time.</p>
]]></description><link>https://forum.cloudron.io/post/37851</link><guid isPermaLink="true">https://forum.cloudron.io/post/37851</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Sat, 16 Oct 2021 10:37:22 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Fri, 15 Oct 2021 22:30:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> said in <a href="/post/37841">Password Reset should be an option for logged-in users too</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> Kinda not so memorable. I can't be the only Sys Admin that gets requests day and night that you have to answer by phone and memory? Can we have a URL rewrite for <code>/password-reset</code>?</p>
</blockquote>
<p dir="auto">why not create a short URL that you'll remember?</p>
]]></description><link>https://forum.cloudron.io/post/37842</link><guid isPermaLink="true">https://forum.cloudron.io/post/37842</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Fri, 15 Oct 2021 22:30:42 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Fri, 15 Oct 2021 21:58:58 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> Kinda not so memorable. I can't be the only Sys Admin that gets requests day and night that you have to answer by phone and memory? Can we have a URL rewrite for <code>/password-reset</code>?</p>
]]></description><link>https://forum.cloudron.io/post/37841</link><guid isPermaLink="true">https://forum.cloudron.io/post/37841</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Fri, 15 Oct 2021 21:58:58 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Thu, 07 Oct 2021 11:53:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> said in <a href="/post/37395">Password Reset should be an option for logged-in users too</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> So what has been implemented is a way to reset the password on behalf of the user as an admin. If I understand you correctly, then you also want a direct link for the user to reset the password on his/her own?</p>
</blockquote>
<p dir="auto">That was my understanding of what <a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> wanted too - for already existing logged in users to be able to reset their own passwords...</p>
<blockquote>
<p dir="auto">This does already exist though: <a href="https://my.example.com/login.html?passwordReset" target="_blank" rel="noopener noreferrer nofollow ugc">https://my.example.com/login.html?passwordReset</a><br />
Would that work for you?</p>
</blockquote>
<p dir="auto">Heh, I think that is exactly what <a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> was after!</p>
<p dir="auto">That should be added to the docs somewhere!</p>
]]></description><link>https://forum.cloudron.io/post/37411</link><guid isPermaLink="true">https://forum.cloudron.io/post/37411</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Thu, 07 Oct 2021 11:53:39 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Thu, 07 Oct 2021 07:47:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> So what has been implemented is a way to reset the password on behalf of the user as an admin. If I understand you correctly, then you also want a direct link for the user to reset the password on his/her own?</p>
<p dir="auto">This does already exist though: <a href="https://my.example.com/login.html?passwordReset" target="_blank" rel="noopener noreferrer nofollow ugc">https://my.example.com/login.html?passwordReset</a><br />
Would that work for you?</p>
]]></description><link>https://forum.cloudron.io/post/37395</link><guid isPermaLink="true">https://forum.cloudron.io/post/37395</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Thu, 07 Oct 2021 07:47:12 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Wed, 06 Oct 2021 20:40:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> Can I get an ETA on this, and what the URL will be please? (ideally something memorable, like <a href="http://my.example.com/password-reset" target="_blank" rel="noopener noreferrer nofollow ugc">my.example.com/password-reset</a>)</p>
]]></description><link>https://forum.cloudron.io/post/37369</link><guid isPermaLink="true">https://forum.cloudron.io/post/37369</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Wed, 06 Oct 2021 20:40:16 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Mon, 13 Sep 2021 13:38:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> Magic - thank you kindly!</p>
<p dir="auto">Often I end up doing support over the phone or SMS without web access, so hoping this will make it easier to verbalise instructions without needing to copy/paste links.</p>
]]></description><link>https://forum.cloudron.io/post/36396</link><guid isPermaLink="true">https://forum.cloudron.io/post/36396</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Mon, 13 Sep 2021 13:38:44 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Mon, 13 Sep 2021 12:10:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> this has been implemented now and will be part of the next release.</p>
]]></description><link>https://forum.cloudron.io/post/36383</link><guid isPermaLink="true">https://forum.cloudron.io/post/36383</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Mon, 13 Sep 2021 12:10:40 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Wed, 08 Sep 2021 13:44:11 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> Sounds good - be happy with that!</p>
]]></description><link>https://forum.cloudron.io/post/36224</link><guid isPermaLink="true">https://forum.cloudron.io/post/36224</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Wed, 08 Sep 2021 13:44:11 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Wed, 08 Sep 2021 11:01:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> I see github and the likes also show a password reset link in the profile. We can do this as well, as it essentially just prefills the regular password reset form with the email address.</p>
<p dir="auto">There are two blocking issues, we need to fix first though:</p>
<ol>
<li>Currently in a login session you could just change the email address right there and then trigger the password reset (this is already a bit of an issue so we will fix this anyways to require the password on email change)</li>
<li>Fix the password reset page to allow prefilling and directly jump into that form unlike now from the login page.</li>
</ol>
]]></description><link>https://forum.cloudron.io/post/36217</link><guid isPermaLink="true">https://forum.cloudron.io/post/36217</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Wed, 08 Sep 2021 11:01:12 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Tue, 31 Aug 2021 12:59:35 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jdaviescoates" aria-label="Profile: jdaviescoates">@<bdi>jdaviescoates</bdi></a> Exactly that. There's no issue with security because it's no different to getting the link when logged out.</p>
<p dir="auto">It is a usability issue, in that you have to first logout to trigger the email reset link.</p>
<p dir="auto">It would also be good if it is always available on a memorable link too, like: <a href="https://my.example.com/password-reset" target="_blank" rel="noopener noreferrer nofollow ugc">https://my.example.com/password-reset</a> as it's easy to then type out, in response to this question that seems to come up a couple of times a month among 60 users.</p>
]]></description><link>https://forum.cloudron.io/post/35907</link><guid isPermaLink="true">https://forum.cloudron.io/post/35907</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Tue, 31 Aug 2021 12:59:35 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Sun, 29 Aug 2021 13:01:41 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> I think the request is basically about adding an "email me a password reset link" button to the existing page where users can change their password (if they know their PW), right <a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> ?</p>
]]></description><link>https://forum.cloudron.io/post/35862</link><guid isPermaLink="true">https://forum.cloudron.io/post/35862</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Sun, 29 Aug 2021 13:01:41 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Sun, 29 Aug 2021 11:56:55 GMT]]></title><description><![CDATA[<p dir="auto">I am not sure what this really is about,  but a user can edit his/her password through the Cloudron dashboard, but of course like with other services at least I am aware of, you have to provide the old password when setting a new one through a login session.</p>
<p dir="auto">Password resets are instead verified by the email with the reset link.</p>
<p dir="auto">I also don't think it is correct to allow password change without some kind of additional verification means otherwise if a valid access token leaks for a user, anyone with that token can change the password.</p>
]]></description><link>https://forum.cloudron.io/post/35852</link><guid isPermaLink="true">https://forum.cloudron.io/post/35852</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Sun, 29 Aug 2021 11:56:55 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Sat, 28 Aug 2021 22:31:08 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/murgero" aria-label="Profile: murgero">@<bdi>murgero</bdi></a> that requires admin intervention, they should be able to do that in a self-service fashion.</p>
]]></description><link>https://forum.cloudron.io/post/35846</link><guid isPermaLink="true">https://forum.cloudron.io/post/35846</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Sat, 28 Aug 2021 22:31:08 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Sat, 28 Aug 2021 21:36:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> Oh! As an admin - why not send them a password reset link? You can do this in 2 clicks under users.</p>
]]></description><link>https://forum.cloudron.io/post/35842</link><guid isPermaLink="true">https://forum.cloudron.io/post/35842</guid><dc:creator><![CDATA[murgero]]></dc:creator><pubDate>Sat, 28 Aug 2021 21:36:47 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Sat, 28 Aug 2021 20:28:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mehdi" aria-label="Profile: mehdi">@<bdi>mehdi</bdi></a> I think it's fairly standard to be able to edit one's password. Normally via something called Profile / Account / Settings or similar</p>
<p dir="auto">e.g. WordPress</p>
<p dir="auto"><a href="https://wordpress.org/support/article/resetting-your-password/" target="_blank" rel="noopener noreferrer nofollow ugc">https://wordpress.org/support/article/resetting-your-password/</a></p>
<p dir="auto">Same thing on <a href="http://cloudron.io" target="_blank" rel="noopener noreferrer nofollow ugc">cloudron.io</a> <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60f.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--smirk" style="height:23px;width:auto;vertical-align:middle" title="😏" alt="😏" /></p>
<p dir="auto"><img src="/assets/uploads/files/1630182373515-screenshot_20210828-212521.png" alt="Screenshot_20210828-212521.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.cloudron.io/post/35836</link><guid isPermaLink="true">https://forum.cloudron.io/post/35836</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Sat, 28 Aug 2021 20:28:17 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Sat, 28 Aug 2021 17:03:06 GMT]]></title><description><![CDATA[<p dir="auto">I don't know of any service that does this.</p>
<p dir="auto">When I am on the other side of this problem, as a user, what I usually do is just open a Icognito browser window and do the reset there.</p>
]]></description><link>https://forum.cloudron.io/post/35835</link><guid isPermaLink="true">https://forum.cloudron.io/post/35835</guid><dc:creator><![CDATA[mehdi]]></dc:creator><pubDate>Sat, 28 Aug 2021 17:03:06 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Fri, 27 Aug 2021 20:51:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> this is only an issue because the user is already logged in, correct? I can look into what other services do.</p>
]]></description><link>https://forum.cloudron.io/post/35819</link><guid isPermaLink="true">https://forum.cloudron.io/post/35819</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Fri, 27 Aug 2021 20:51:56 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Fri, 27 Aug 2021 20:43:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> Use case:</p>
<p dir="auto">User: Marcus, what's my Password?</p>
<p dir="auto">Marcus: IDK, try resetting it at <a href="http://my.example.com" target="_blank" rel="noopener noreferrer nofollow ugc">my.example.com</a></p>
<p dir="auto">That's where the conversation should then end - yet it does not.</p>
<p dir="auto">I've presented the problem and the solution, the rest's up to you <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title=";)" alt="😉" /></p>
]]></description><link>https://forum.cloudron.io/post/35818</link><guid isPermaLink="true">https://forum.cloudron.io/post/35818</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Fri, 27 Aug 2021 20:43:36 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Fri, 27 Aug 2021 20:41:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/murgero" aria-label="Profile: murgero">@<bdi>murgero</bdi></a> Not really, they would need access to both a logged in browser and email.</p>
]]></description><link>https://forum.cloudron.io/post/35817</link><guid isPermaLink="true">https://forum.cloudron.io/post/35817</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Fri, 27 Aug 2021 20:41:55 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Fri, 27 Aug 2021 16:25:40 GMT]]></title><description><![CDATA[<p dir="auto">You can also login in anonymous mode and get to password reset.</p>
]]></description><link>https://forum.cloudron.io/post/35804</link><guid isPermaLink="true">https://forum.cloudron.io/post/35804</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Fri, 27 Aug 2021 16:25:40 GMT</pubDate></item><item><title><![CDATA[Reply to Password Reset should be an option for logged-in users too on Fri, 27 Aug 2021 16:03:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> I just have my users use bitwarden lol IDK if a password reset link while logged in is a smart idea cause that allows anyone with access to their browser to just change the password.</p>
]]></description><link>https://forum.cloudron.io/post/35802</link><guid isPermaLink="true">https://forum.cloudron.io/post/35802</guid><dc:creator><![CDATA[murgero]]></dc:creator><pubDate>Fri, 27 Aug 2021 16:03:52 GMT</pubDate></item></channel></rss>