Bug #1915

RIB - UAT: Login issue for User ID # Pentest1

Added by Norhaidah Md Dasuki over 11 years ago. Updated over 11 years ago.

Status:Development / Work In ProgressStart date:January 29, 2013
Priority:NormalDue date:January 30, 2013
Assignee:Norhaidah Md Dasuki% Done:

100%

Category:LoginSpent time:-
Target version:-

Description

Issue: User required to do Force Change Password every time login to the system (UAT environment).

Test Scenario:-
1st Step

Go to http://10.6.6.20:9081/rib.uat/common/Login.do
Enter Username Pentest1
Click on Next button

System go to Force Change Password page

Enter information as below:-used

Enter old password 1111bbbb
Enter new password 1111cccc

Successful Change Password and go to Home page

2nd Step

Logout system, refresh and try to login back
System still required to force change password after enter Username and click on Next button.
Used the same password information as above

Successful Change Password and go to Home page
Logout and login again. System still asking to change password again.

History

#1 Updated by Alwi Husada over 11 years ago

  • Status changed from New - Begin Life Cycle to Internal Testing
  • Assignee changed from Alwi Husada to Norhaidah Md Dasuki
  • % Done changed from 0 to 100

Salam kak Haida,

Actually this Force Change password is not successful Due to PASSWORD_COMPLEXITY Setting in Upass.cfg has been change to 1, the new password 1111cccc is rejected by the Upass due to weak password, (New Password must content mixture at least 1 Capital letter, 1 small letter, 1 Special character and 1 numeric), but the RIB is not show correct error message and allow the user to pass through,

Amended the RIB to display error message when entered weak password instead of allow user to pass through,
Kindly do-retest in UAT environment,

Note:
Username:pentest1
Password:Abcd!@34

Thanks,

#2 Updated by Norhaidah Md Dasuki over 11 years ago

  • Status changed from Internal Testing to Development / Work In Progress
  • Assignee changed from Norhaidah Md Dasuki to Alwi Husada
  • % Done changed from 100 to 80

Hi Alwi,

Currently, as per required and agreed by Agrobank on the password requirement for phase 1 is as below message. Please verify and change accordingly.

< Your Password must contain a mixture of alphanumeric format with a minimum of 8 to 12 characters, upper, lower case alphabets and special characters but not include this special character ["<>&%+].>

#3 Updated by Alwi Husada over 11 years ago

  • Assignee changed from Alwi Husada to Norhaidah Md Dasuki
  • % Done changed from 80 to 100

salam kak haida,

Amended error message as per requested, kindly re-test on UAT,

Thanks,

Also available in: Atom PDF