randygit / -mlq

MIT License
0 stars 0 forks source link

System admin creates account for people qualified to use the system #1

Open randygit opened 8 years ago

randygit commented 8 years ago
randygit commented 8 years ago

valid roles are:

randygit commented 8 years ago

we can leave out temporary token, just a link to the login page.

jotom commented 8 years ago

Just make the account active once logged in. Even if they don't want to change passwords. Adding a verification stage and putting status of user as pending would only add an extra step to check if password changed. Save extra use case/resources in case they have a mandatory change password rule every three months.