[OPEN] Users cannot change password if current password is set as forbidden word

Canvas

Engineers are currently investigating the issue.

Description

When using a TXT file to upload a list of forbidden words/terms for passwords, if a word is used that is already in a user's current password, they will not be able to change their password. An "Unexpected error" is seen when trying to save the password.

Expected Behavior

Users should be able to change their passwords if their current password is included in the forbidden words list.

Workaround

No workaround exists at this time.

Steps to Reproduce

Prerequisite: Enable Enhance password options under account features.

  1. As a user, set your password.

  2. Create a TXT file with the password you just set on a single line in the file and save it

  3. Go to the account authentication setting page

  4. Click “View Options” under the canvas auth provider

  5. Upload the txt file as a forbidden words list and save your changes

  6. As the same user you set the password on, try changing your password to anything else.

Additional Info

FOO-4974


Known issues indicate notable behaviors that have been escalated to the Canvas engineering team. Known issues are not a guarantee for an immediate resolution. This document is for informational purposes only and does not replace the Support process. If you are encountering the behavior outlined in this document, please ensure you have submitted a Support case (per your institution's escalation process) so Canvas Support can adequately gauge the overall customer impact and prioritize appropriately.

Labels (1)
Tags (1)