Skip to main content

Question

Change Password using API

10 months ago
OfflineJosé Luis Cerrada
José Luis Cerrada

It would be very useful for our administrators to change an user's password. Taking a glance on the API, it seems that the only way to do it is by requesting a password reset and emailing the user to obtain the token. Is there any way to take the user out of this process?

Thanks for your support.

-----
You had this question too3 people have this question.
 
Answered

0 Answers:

5 Replies

OfflineBryan Willey Bryan Willey said 10 months ago

There is no way to remove the user from the process. Because we use single sign on a user can access multiple communities with their username and password it would create a huge security vulnerability if passwords could be reset without a users consent.


OfflinePaul Estes Paul Estes said 10 months ago

I agree that Administrators should have more control over community member accounts.  For Social Networks, I can understand why this is limited; however, for Business Networks administrators should have the ability to create accounts, reset passwords, change member profile information, etc. - as well as the ability to lock these things down so that members cannot change them.

Igloo made a great step in this direction recently by allowing the ability for Administrators to "Add Members" from the Control Panel\Manage Members area.  This allows an admin to create the accounts in advance.  However, once you "turn over" that account to the member, they can modify all of their information, including changing of their password (which is actually a good thing).  But what if an admin needs to go in an change some profile info for a member, or perhaps subscribe them to new forum(s)?  He/She must ask for the member's password, login as them, make the change and then tell the member to change their password again.

I would recommend a model similar to Moodle's, whereby the admin has complete control over the member's account, but also allow the ability to force password change upon next login.  I find this to be a very useful model.  Furthermore, if the member forgets their password, it is easy to go in and change the password, provide the access and then force a password change upon login.

While I understand that José is asking for this capability in the API, I would suggest that the same functionality and control be provided through the Manage Members interface as well.


OfflinePaul Estes Paul Estes said 10 months ago

@Bryan - Seems we were posting at the same time :)

I see your point about the SSO with logons across communities, and understand how this complicates things. Let me think about this one some more as I was only considering a one-dimensional approach to this problem.


OfflineMichael Dieterle Michael Dieterle said 4 months ago

I agree with both Jose and Paul. In the scenario of a closed business site, it makes a lot of sense. With IGLOO broadening their target audiences, you also need to expand functionality for new use cases!


OfflineGarry Miller Garry Miller said 4 months ago

@Michael

Me too !


Would you like to comment?

You must be a member. Sign In if you are already a member.

  • 137 views
  • $obj.VersionIndex versions
  • 5 replies
  • 2 followers
     
Post Date:
July 7, 2011
Posted By:
José Luis Cerrada

About this forum

  • 3,309 views
  • 9 topics
  • 2 followers
     

Access allows you to control who can see your information and what actions they can preform - such as adding versions. Have questions about Access and how it applies to your community? Post your question and we'll get back to you!


Viewed 137 times