Skip to Content Skip to Menu

Backend profile edit requires user password verification

  • endoc
  • endoc
  • OFFLINE
  • Posts: 94
  • Thanks: 4
  • Karma: 0
5 years 8 months ago #310806 by endoc
I would like to some of the custom profile fields via the backend, however, when I try to exit and save I am prompted to verify the user's password. Is there a way around this?

Please Log in or Create an account to join the conversation.

  • Astrid
  • Astrid
  • OFFLINE
  • Posts: 183
  • Thanks: 68
  • Karma: 10
5 years 8 months ago #310809 by Astrid
Are you using a password add-on like Lastpass?

Please Log in or Create an account to join the conversation.

  • endoc
  • endoc
  • OFFLINE
  • Posts: 94
  • Thanks: 4
  • Karma: 0
5 years 8 months ago #310810 by endoc
No, just the standard CB and CBSubs extensions/plugins.

I just realized that my initial post was a little confusing. To clarify, the problem occurs only while editing a users profile in the admin backend. After making the changes, I am prompted to complete their password verification before they can be saved. It is as if the "Verify Password" field is left blank but required. As a workaround, I have been required to change their password to a temp pw and then have to contact them to login an change it back to one that they prefer.

Here is another probably but possibly unrelated concern: I also notice that even while logged in to the frontend the site will occasionally ask for users to relogin when accessing ACL-protected content, such as a forum or article. What is strange is that the user is already logged in (according to what is displayed on visible profile module sidebar). The problem here is an error banner will pop up saying something like "You do not have access to that resource", but after logging out and then back in, it will grant access. Why would the site report a user is logged in, but then require a relogin to access the content?

Please Log in or Create an account to join the conversation.

  • krileon
  • krileon
  • ONLINE
  • Posts: 48441
  • Thanks: 8275
  • Karma: 1443
5 years 8 months ago #310827 by krileon
You're being asked to verify the password because your browsers autocomplete is filling in your password into the password input while editing that user. We already set autocomplete="off" for both the password input and the form. However browser extensions like LastPass ignore this and fill it in anyway. Some browsers themselves may do the same.

Your options are to configure LastPass or whatever password manager you're using to stop autofilling or to empty the password input before saving their profile.

Here is another probably but possibly unrelated concern: I also notice that even while logged in to the frontend the site will occasionally ask for users to relogin when accessing ACL-protected content, such as a forum or article. What is strange is that the user is already logged in (according to what is displayed on visible profile module sidebar). The problem here is an error banner will pop up saying something like "You do not have access to that resource", but after logging out and then back in, it will grant access. Why would the site report a user is logged in, but then require a relogin to access the content?

CB does not control Joomlas ACL. That'd entirely be on Joomla and sounds like a caching issue.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in or Create an account to join the conversation.

Moderators: beatnantkrileon
Powered by Kunena Forum