Details
-
New Feature
-
Status: Closed
-
Should
-
Resolution: Fixed
-
None
-
None
-
None
-
Medium
Description
User accounts in the OpenMRS Platform are secured with password hashes and salt; however, because OpenMRS did not historically include the ability to send email, the process for resetting password has been less than ideal. Currently, an administrator sets a temporary password or a user answers their "secret question" (a question and answer set the user previously provided). A medical record system should have a stronger approach to password security and not even an administrator should ever know a user's password (even temporarily). The current approach also puts an undue burden on administrators to reset passwords for users who have forgotten them.
For more details see the GSoC 2018 project page
Gliffy Diagrams
Attachments
Issue Links
- is depended on by
-
RESTWS-722 Allow a user to request for a password reset via email
-
- Closed
-
- is related to
-
RESTWS-749 Add REST support for requesting and resetting password via email
-
- Closed
-