-
Notifications
You must be signed in to change notification settings - Fork 8.1k
Closed
Labels
kind/enhancementCategorizes a PR related to an enhancementCategorizes a PR related to an enhancementrelease/26.4.0team/core-iam
Description
Description
Why: Password resets were implicitly granted by MANAGE_USERS. With FGAP v2 we need policy-based, auditable control to allow/deny resets per user/group with deny-overrides and secure-by-default behavior.
What:
- Add
reset-passwordscope toUSERS - Require
RESET_PASSWORDinUserResource.resetPassword() UserPermissionsV2implements deny-overrides, secure-by-default; optional fallback to MANAGE_USERS viafgap.v2.resetPassword.fallbackToManageUsers(default=false)getAccess(user).resetPasswordfor Admin Console- Preserve self-service password change
- Logging/auditing enhancements
- Tests and docs
Migration notes: When FGAP v2 is enabled and no RESET_PASSWORD policies exist, reset is denied by default unless fallback is enabled.
Discussion
No response
Motivation
No response
Details
No response
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
kind/enhancementCategorizes a PR related to an enhancementCategorizes a PR related to an enhancementrelease/26.4.0team/core-iam