Commit 35204f62 authored by Kirill Roskolii's avatar Kirill Roskolii Committed by Paulo Henrique Cota Starling
Browse files

Issue #3092396 by simbaw, omkar06, RoSk0, manish.upadhyay, AohRveTPV: Do not...

Issue #3092396 by simbaw, omkar06, RoSk0, manish.upadhyay, AohRveTPV: Do not force SSO based user to change password
parent 6be578cd
Loading
Loading
Loading
Loading
+1 −0
Changes for README.md: 1 added line, 0 removed lines.
Original line number Diff line number Diff line
@@ -51,3 +51,4 @@ for constraints and the constraint's policies
to his/her user form upon expiration
-  Password time-based expiration leverages cron for tagging accounts as
 expired
- Externally authenticated users (via `externalauth` module) are excluded from validation and time-based expiration
+22 −0
Changes for password_policy.module: 22 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -226,6 +226,16 @@ function _password_policy_user_profile_form_validate(&$form, FormStateInterface
    return;
  }

  // Check if user is authenticated externally.
  if (\Drupal::moduleHandler()->moduleExists('externalauth')) {
    $authmap = \Drupal::service('externalauth.authmap');
    $account = $form_state->getFormObject()->getEntity();
    $external_ids = $authmap->getAll($account->id());
    if ($external_ids) {
      return;
    }
  }

  $expiration = $form_state->getValue('field_password_expiration');
  if (!is_null($expiration) && $expiration['value'] === FALSE) {
    $form_state->setValue('field_password_expiration', ['value' => 0]);
@@ -406,6 +416,18 @@ function password_policy_cron() {

        $valid_list = $query->execute();

        // Check for externally authenticated users.
        if (\Drupal::moduleHandler()->moduleExists('externalauth')) {
          $authmap = \Drupal::service('externalauth.authmap');
          foreach ($valid_list as $key => $uid) {
            $external_ids = $authmap->getAll($uid);
            if ($external_ids) {
              // Exclude externally authenticated users.
              unset($valid_list[$key]);
            }
          }
        }

        // Load User Objects.
        $users = \Drupal::entityTypeManager()
          ->getStorage('user')