Skip to content

When password expiration is enabled, accounts without a stored pwd_last_updated timestamp are not treated as expired #924

@miaulalala

Description

@miaulalala

When password expiration is enabled, accounts without a stored pwd_last_updated timestamp are not treated as expired. Instead, the first successful login recreates the timestamp with the current time and allows access. This lets pre-existing local accounts bypass the expiration policy without changing their password.

App version observed: password_policy 5.0.0
Nextcloud 33.0.2

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions