Re: mustChangePassword flag intended use?

2018-10-25 Thread Francesco Chicchiriccò
On 23/10/18 10:49, Lukas Funk wrote: Hi Francesco I’ve created a JIRA issue - https://issues.apache.org/jira/browse/SYNCOPE-1388 But I tend to disagree with the behavior about allowing to get the user information. IMHO whenever the flag is set, any request should return 403 except the

RE: mustChangePassword flag intended use?

2018-10-23 Thread Lukas Funk
Hi Francesco I’ve created a JIRA issue - https://issues.apache.org/jira/browse/SYNCOPE-1388 But I tend to disagree with the behavior about allowing to get the user information. IMHO whenever the flag is set, any request should return 403 except the paths /accesstoken and

Re: mustChangePassword flag intended use?

2018-10-23 Thread Francesco Chicchiriccò
Hi Lukas, On 22/10/18 15:37, Lukas Funk wrote: Hi, I’ve a question regarding «mustChangePassword» flag for users. How is the behavior for this flag intended? I’d expect, that if this flag is set, I can obtain a temporary access token but I can’t perform any actions other than