Summary
Fleetbase\Http\Controllers\Internal\v1\UserController::setCurrentUserPassword() (POST /int/v1/users/set-password) is missing the #[SkipAuthorizationCheck] attribute that its sibling "current user" endpoints have (changeCurrentUserEmail, acceptCompanyInvite, setUserLocale, …). The authorization layer therefore applies the default permission for a POST on users, which is create user.
Impact
A newly invited user who is not an administrator cannot set their initial password. After accepting the invitation, the console opens the "Set a new password" modal (needs_password: true), and saving it fails with:
User is not authorized to create user
The modal has no close/decline button, so the user is stuck. Administrators are not affected because they hold the create user permission, which hides the bug.
Versions
Fleetbase v0.7.63 (core-api v1.6.62).
Reproduction
- IAM → Users → invite a new user with a non-admin role (e.g. Operations Manager from Fleet-Ops).
- Accept the invitation from the email.
- Enter and confirm a password in the "Set a new password" modal →
POST /int/v1/users/set-password → error "User is not authorized to create user".
Suggested fix
#[SkipAuthorizationCheck]
public function setCurrentUserPassword(UpdatePasswordRequest $request)
The method only acts on $request->user(), so it needs authentication but no IAM permission.
Workaround
The invited user (already active after accepting) uses "Forgot your password?" on the login page to set the password by email.
Summary
Fleetbase\Http\Controllers\Internal\v1\UserController::setCurrentUserPassword()(POST /int/v1/users/set-password) is missing the#[SkipAuthorizationCheck]attribute that its sibling "current user" endpoints have (changeCurrentUserEmail,acceptCompanyInvite,setUserLocale, …). The authorization layer therefore applies the default permission for aPOSTonusers, which is create user.Impact
A newly invited user who is not an administrator cannot set their initial password. After accepting the invitation, the console opens the "Set a new password" modal (
needs_password: true), and saving it fails with:The modal has no close/decline button, so the user is stuck. Administrators are not affected because they hold the
create userpermission, which hides the bug.Versions
Fleetbase v0.7.63 (core-api v1.6.62).
Reproduction
POST /int/v1/users/set-password→ error "User is not authorized to create user".Suggested fix
The method only acts on
$request->user(), so it needs authentication but no IAM permission.Workaround
The invited user (already active after accepting) uses "Forgot your password?" on the login page to set the password by email.