[GH-ISSUE #686] Feature Request: Ability for users to reset their own passwords #2385

Closed
opened 2026-03-14 03:48:18 +03:00 by kerem · 7 comments
Owner

Originally created by @r3die on GitHub (Sep 2, 2021).
Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/686

Is your feature request related to a problem? Please describe.
Users cannot change their own passwords without having the 'Manage User Accounts' permission which would give them the ability to change other user passwords as well.

Describe the solution you'd like
'Change Password' option upon signing in for users without the 'Manage User Accounts' permission/ 'Forgot Password' option prior to login.

Originally created by @r3die on GitHub (Sep 2, 2021). Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/686 **Is your feature request related to a problem? Please describe.** Users cannot change their own passwords without having the 'Manage User Accounts' permission which would give them the ability to change other user passwords as well. **Describe the solution you'd like** 'Change Password' option upon signing in for users without the 'Manage User Accounts' permission/ 'Forgot Password' option prior to login.
kerem 2026-03-14 03:48:18 +03:00
  • closed this issue
  • added the
    bug
    fixed
    labels
Author
Owner

@iTQuanNet commented on GitHub (Sep 3, 2021):

I don't think this is a good suggestion. There is a certain risk. The password and token can be reset by the administrator. The user only needs to confirm with the administrator.

<!-- gh-comment-id:912199595 --> @iTQuanNet commented on GitHub (Sep 3, 2021): I don't think this is a good suggestion. There is a certain risk. The password and token can be reset by the administrator. The user only needs to confirm with the administrator.
Author
Owner

@r3die commented on GitHub (Sep 3, 2021):

I don't think it is unreasonable for users to have the ability to change their own passwords. Every Enterprise platform has this functionality- in fact I find it less secure that I am creating passwords for technical users that they cannot change. To mitigate your concern, as long as they don't have the 'Manage User Accounts' permission the Global/Super admin can still go in and lock their account if they are terminated from the organization.

<!-- gh-comment-id:912527530 --> @r3die commented on GitHub (Sep 3, 2021): I don't think it is unreasonable for users to have the ability to change their own passwords. Every Enterprise platform has this functionality- in fact I find it less secure that I am creating passwords for technical users that they cannot change. To mitigate your concern, as long as they don't have the 'Manage User Accounts' permission the Global/Super admin can still go in and lock their account if they are terminated from the organization.
Author
Owner

@wh1te909 commented on GitHub (Sep 3, 2021):

yea this is more like a bug than a feature request, users should already be able to reset their own passwords. will fix

<!-- gh-comment-id:912616275 --> @wh1te909 commented on GitHub (Sep 3, 2021): yea this is more like a bug than a feature request, users should already be able to reset their own passwords. will fix
Author
Owner

@r3die commented on GitHub (Sep 3, 2021):

@wh1te909 Sounds good- Are standard users intended to perform the action by right clicking on their user account within Settings>User Administration?

<!-- gh-comment-id:912628918 --> @r3die commented on GitHub (Sep 3, 2021): @wh1te909 Sounds good- Are standard users intended to perform the action by right clicking on their user account within Settings>User Administration?
Author
Owner

@wh1te909 commented on GitHub (Sep 3, 2021):

@wh1te909 Sounds good- Are standard users intended to perform the action by right clicking on their user account within Settings>User Administration?

yep

<!-- gh-comment-id:912676975 --> @wh1te909 commented on GitHub (Sep 3, 2021): > @wh1te909 Sounds good- Are standard users intended to perform the action by right clicking on their user account within Settings>User Administration? yep
Author
Owner

@wh1te909 commented on GitHub (Sep 4, 2021):

changes pushed, will be in next release

<!-- gh-comment-id:913047949 --> @wh1te909 commented on GitHub (Sep 4, 2021): changes pushed, will be in next release
Author
Owner

@wh1te909 commented on GitHub (Sep 6, 2021):

added in release 0.8.3

<!-- gh-comment-id:913502238 --> @wh1te909 commented on GitHub (Sep 6, 2021): added in release 0.8.3
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/tacticalrmm#2385
No description provided.