Skip to content

Create Users on password reset requests #6458

@rjsparks

Description

@rjsparks

We have people who for whatever reason had a Person record with no User record created decades ago, usually because they were a co-author on a draft. Now when they want to interact with the datatracker (using the same email that was associated with that Person decades ago), the password reset link says it sent something, but it didn't send anything because there was no User.

Instead, create a User in this situation. Tie in the logic that looks for possible duplicate persons and send the warning message to the secretariat (that code already exists).

The security posture of the result should be the same as a password reset for a Person that already has a User - proof of control of the email address.

(If that turns out to be problematic, change this issue to tell the person that they need to contact the secretariat to establish a new password instead).

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions