Relationship Graph

Relationship Graph
related to related to child of child of duplicate of duplicate of

View Issue Details

IDProjectCategoryView StatusLast Update
0037425mantisbtauthenticationpublic2026-09-28 09:04
Reporterricardoalonsos Assigned Tocommunity  
PrioritynormalSeveritytweakReproducibilityalways
Status acknowledgedResolutionopen 
Product Version2.28.4 
Summary0037425: With $g_login_method = LDAP, the local password is never used
Description

With $g_login_method = LDAP, the local password is never used:

  • auth_does_password_match() returns ldap_authenticate() directly when the
    configured login method is LDAP, with no fallback to the database password;
  • ldap_authenticate_by_username() overwrites the stored hash with the LDAP
    password on every successful login.

So the password an administrator types on manage_user_create_page.php cannot
ever be used. The form invites them to choose a credential that has no effect.

manage_user_edit_page.php already suppresses the equivalent control via
auth_can_set_password(); the create page has no comparable check.

Change

Hide the password fields on the create page when the login method is LDAP, and
skip the matching empty_password_sure_msg confirmation in
manage_user_create.php.

The second half matters: that confirmation fires whenever the submitted
password is blank, so hiding the field without it would add an extra
confirmation step to every user creation under LDAP.

Notes on the approach

auth_can_set_password() would be the natural helper, but it cannot be used
here: it calls auth_flags(), which throws ClientException for a user id of
0 with a blank username, and on the create page no user exists yet.

The explicit LDAP != config_get_global( 'login_method' ) test is instead the
form already used in signup_page.php, login_password_page.php,
lost_pwd_page.php and print_api.php.

Tests

No new tests: the change is display logic on a page the suite does not
exercise. Verified that the existing suite is unaffected — 395 tests, no new
failures, against MariaDB 11 on PHP 8.3.

TagsNo tags attached.

Relationships

related to 0024023 new auth_does_password_match() - use user auth_flags() 

Activities

dregad

dregad

2026-09-28 08:12

developer   ~0071474

PR https://github.com/mantisbt/mantisbt/pull/2290

dregad

dregad

2026-09-28 09:00

developer   ~0071477

auth_can_set_password() would be the natural helper, but it cannot be used
here: it calls auth_flags(), which throws ClientException for a user id of
0 with a blank username, and on the create page no user exists yet.

This problem has been reported before, see 0024023