Allow users to manage their own passwords and set up own accounts
Avec réponseIt seems to be a security flaw that we are setting up passwords for our users and sending them notifications of what their passwords are. Feature requests would be either:
- Prompt user to reset their password upon first login (in mobile app or web app) when password was set for them
- Allow us to invite a user-- they receive an email, click a link, set up their account (including password) themselves
Thanks!
-
Commentaire officiel
Hi everyone,
I had a chance to chat to the team about this and they let me know that setting up users (including passwords) at the organization level has been designed that way on purpose. There are a few reasons for this, including the fact that users need to be tied to roles and also for security reasons (i.e. making sure that there is oversight on everyone being set up in the system). This is not something that they are currently considering changing, however, if interest persists it may be something to reconsider in future.
Thank you all for your input and feedback!
Alex
Actions pour les commentaires -
Actually I just discovered that users cannot reset their own passwords at all without having the permission to reset ALL employee passwords. This is a critical feature request. Employees should be able to manage and reset their own passwords without having the ability to change passwords of others.
-
I would also like to chime in and support having a prompt for users to reset their password when they log in using a password created for them by one of the admins.
Perhaps an option on the web interface when admins go to the change password popup to force the user to make a new password upon their next login.
Vous devez vous connecter pour laisser un commentaire.
Commentaires
7 commentaires