Repository navigation
bug(settings): an SSO account is offered a Change password form it cannot use #850
Copy link
Copy link
Closed
Labels
area:frontendReact, /srcReact, /srcarea:securityCybersecurity and threat intelligenceCybersecurity and threat intelligenceauthenticationAuthenticationAuthenticationpriority:P3Later planned capabilityLater planned capabilitypriority:P3-lowNice to haveNice to havestatus:in-reviewPR openPR opentier:4-uxUX: polish on top of a working engineUX: polish on top of a working enginetype:bugSomething is brokenSomething is brokenux
Milestone
Description
Activity
- addedarea:securityCybersecurity and threat intelligenceCybersecurity and threat intelligencepriority:P3Later planned capabilityLater planned capabilityauthenticationAuthenticationAuthenticationtype:bugSomething is brokenSomething is brokenarea:frontendReact, /srcReact, /srcpriority:P3-lowNice to haveNice to havestatus:readyMeets the ready definitionMeets the ready definitiontier:4-uxUX: polish on top of a working engineUX: polish on top of a working enginestatus:in-progressAn agent is working itAn agent is working itand removedstatus:readyMeets the ready definitionMeets the ready definition
on Sep 30, 2026 - added a commit that references this issue
on Sep 30, 2026 frontend-react — 2026-09-30
Done — PR #852, stacked on #848. Commit
5ff644db:ChangePasswordCard.tsx: skeleton, then the IdP message, the form, or a fallback to the formuseHasLocalPassword.ts(new)authService.ts:fetchHasLocalPassword, whichfetchDisableMFAProofnow reuses__tests__/changePasswordCard.test.tsx: 3 new tests, and the 4 existing ones adapted to the QueryClient
Verified — card tests 7/7 on 3 runs;
tscandeslintOK;auth+settings+sharedsuites 384/384 on 7 of 8 runs. Live on PG 16 with the real UI: a password account sees 3 fields; an SSO account sees the message, 0 fields and 0 requests; dark-theme contrast is about 9:1.Criteria — 1 ✅ · 2 ✅ · 3 ✅ · 4 ✅ (existing key, no new one) · 5 ✅
Next — Owner review of #852, after #848.
Blocked on — #848 (merge order). Note: one suite run had 2 failures that I couldn't name or reproduce afterwards (7 green runs).
- addedstatus:in-reviewPR openPR openand removedstatus:in-progressAn agent is working itAn agent is working it
on Sep 30, 2026 - linked a pull request that will close this issuefix(settings): tell an SSO account its password lives at the identity provider (#850) #852
on Oct 2, 2026 - added a commit that references this issue
on Oct 2, 2026
Metadata
Metadata
Assignees
Labels
area:frontendReact, /srcReact, /srcarea:securityCybersecurity and threat intelligenceCybersecurity and threat intelligenceauthenticationAuthenticationAuthenticationpriority:P3Later planned capabilityLater planned capabilitypriority:P3-lowNice to haveNice to havestatus:in-reviewPR openPR opentier:4-uxUX: polish on top of a working engineUX: polish on top of a working enginetype:bugSomething is brokenSomething is brokenux
Problem
A user who signs in through an identity provider has no password in OpenRisk. Settings › Security still shows them the Change password card (
frontend/src/features/auth/ChangePasswordCard.tsx, mounted inSettingsScreen.tsx) with a "current password" field they can't fill. They only find out after typing something and submitting, when the server answers 409no_local_passwordand the card switches to a "managed by your identity provider" message (setManagedByIdp).That's a dead end: a form that can't succeed, a password prompt that looks like a phishing pattern to a careful user, and a failed request logged against their account.
GET /auth/mehas returnedhas_passwordsince #754 (PR #848), so the client can know this before rendering anything.Acceptance criteria
/auth/mesayshas_password: false, the card shows no password fields. It explains, in FR and EN, that the password is managed by the identity provider, reusing the existingmanagedByIdpmessage.has_passwordis true, the card is unchanged./auth/meis loading, the card shows a skeleton, not the form. If the read fails, the card falls back to today's form: the server's 409 still switches it to the message, so nothing gets worse.has_password: false; the form fortrue; the form plus the 409 fallback when the read fails.Definition of Done
vitest,tscandeslintgreen on the touched files.