Skip to content

Invited non-admin users cannot set their password: set-password requires 'create user' permission #263

Description

@wespinosar

Summary

Fleetbase\Http\Controllers\Internal\v1\UserController::setCurrentUserPassword() (POST /int/v1/users/set-password) is missing the #[SkipAuthorizationCheck] attribute that its sibling "current user" endpoints have (changeCurrentUserEmail, acceptCompanyInvite, setUserLocale, …). The authorization layer therefore applies the default permission for a POST on users, which is create user.

Impact

A newly invited user who is not an administrator cannot set their initial password. After accepting the invitation, the console opens the "Set a new password" modal (needs_password: true), and saving it fails with:

User is not authorized to create user

The modal has no close/decline button, so the user is stuck. Administrators are not affected because they hold the create user permission, which hides the bug.

Versions

Fleetbase v0.7.63 (core-api v1.6.62).

Reproduction

  1. IAM → Users → invite a new user with a non-admin role (e.g. Operations Manager from Fleet-Ops).
  2. Accept the invitation from the email.
  3. Enter and confirm a password in the "Set a new password" modal → POST /int/v1/users/set-password → error "User is not authorized to create user".

Suggested fix

#[SkipAuthorizationCheck]
public function setCurrentUserPassword(UpdatePasswordRequest $request)

The method only acts on $request->user(), so it needs authentication but no IAM permission.

Workaround

The invited user (already active after accepting) uses "Forgot your password?" on the login page to set the password by email.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions