NeskireDK 5025d06c00 Allow SSO sessions to set a password without the current one
Accounts provisioned by trusted-header SSO get a random password the user
never saw, so /change_password was unusable for them. When the trusted
header asserts the same email as the session user, waive the current
password check and hide the field, so native clients (Yattee) can be given
a password to log in with.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-12 21:02:26 +02:00
..