Issue
When I want to updates a user's password as an administrator, the system does not require to re-enter my own password for authentication. This is inconsistent with other actions, such as updating a screen name or email address, where password verification is required.
Is it possible to enforce the same security check for password updates?
Environment
- Quarterly Releases
Resolution
Currently, this feature does not exist within Liferay. An administrator is not required to re-enter their password when changing another user's password.
A feature request has been created to address this potential security enhancement in a future release. You can monitor the status of this request by following the ticket below: