Enabling password invalidation
Password invalidation, when enabled, requires HCL Commerce users to change their password if the user's password is expired. In this case, the user is redirected to a page where they are required to change their password. Users are not able to access any secure pages on the site until they change their password.
Procedure
- To use the password invalidation security feature, define the ChangePassword view for your store as described in Password invalidation.
- Open the configuration file.
-
Find the
<PasswordInvalidation>
element. Set theenabled
attribute totrue
.<PasswordInvalidation enabled="true"/>
What to do next
Commands can be configured to be exempted from the password invalidation feature. By
default, the following commands are exempt as they involve changing or resetting a users password:
- ChangePassword
- ResetPassword
- AjaxResetPassword
- PersonChangeServicePasswordReset
- AjaxPersonChangeServicePasswordReset
Additional commands can be exempted by specifying the command in a custom properties file \xml\PasswordInvalidationExemptionExtension.properties.