Skip to content

bug(settings): an SSO account is offered a Change password form it cannot use #850

Description

@alex-dembele

Problem

A user who signs in through an identity provider has no password in OpenRisk. Settings › Security still shows them the Change password card (frontend/src/features/auth/ChangePasswordCard.tsx, mounted in SettingsScreen.tsx) with a "current password" field they can't fill. They only find out after typing something and submitting, when the server answers 409 no_local_password and the card switches to a "managed by your identity provider" message (setManagedByIdp).

That's a dead end: a form that can't succeed, a password prompt that looks like a phishing pattern to a careful user, and a failed request logged against their account.

GET /auth/me has returned has_password since #754 (PR #848), so the client can know this before rendering anything.

Acceptance criteria

  1. When /auth/me says has_password: false, the card shows no password fields. It explains, in FR and EN, that the password is managed by the identity provider, reusing the existing managedByIdp message.
  2. When has_password is true, the card is unchanged.
  3. While /auth/me is loading, the card shows a skeleton, not the form. If the read fails, the card falls back to today's form: the server's 409 still switches it to the message, so nothing gets worse.
  4. The account-security i18n keys stay at FR/EN parity.
  5. Tests: the card renders the message and no fields for has_password: false; the form for true; the form plus the 409 fallback when the read fails.

Definition of Done

  • Criteria met; vitest, tsc and eslint green on the touched files.
  • A live pass in a real browser with an SSO-style account (no local password) and a password account, in both themes.

Activity

  1. added this to the trust-v1 milestone on Sep 30, 2026
  2. added
    area:securityCybersecurity and threat intelligence
    priority:P3Later planned capability
    type:bugSomething is broken
    status:readyMeets the ready definition
    tier:4-uxUX: polish on top of a working engine
    and removed
    status:readyMeets the ready definition
    on Sep 30, 2026
  3. alex-dembele commented on Sep 30, 2026

    @alex-dembele
    MemberAuthor

    frontend-react — 2026-09-30

    Done — PR #852, stacked on #848. Commit 5ff644db:

    • ChangePasswordCard.tsx: skeleton, then the IdP message, the form, or a fallback to the form
    • useHasLocalPassword.ts (new)
    • authService.ts: fetchHasLocalPassword, which fetchDisableMFAProof now reuses
    • __tests__/changePasswordCard.test.tsx: 3 new tests, and the 4 existing ones adapted to the QueryClient

    Verified — card tests 7/7 on 3 runs; tsc and eslint OK; auth+settings+shared suites 384/384 on 7 of 8 runs. Live on PG 16 with the real UI: a password account sees 3 fields; an SSO account sees the message, 0 fields and 0 requests; dark-theme contrast is about 9:1.

    Criteria — 1 ✅ · 2 ✅ · 3 ✅ · 4 ✅ (existing key, no new one) · 5 ✅

    Next — Owner review of #852, after #848.

    Blocked on — #848 (merge order). Note: one suite run had 2 failures that I couldn't name or reproduce afterwards (7 green runs).

  4. added a commit that references this issue on Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions