Skip to content

Allow passing null to user reset_password

Ryan Ahearn requested to merge allow-skipping-reset-password into main

Changes proposed in this pull request:

  • allows passing null for user.reset_password - this mainly allows us to import existing users into terraform state without forcing a recreation

Things to check

  • For any logging statements, is there any chance that they could be logging sensitive data?
  • Are log statements using a logging library with a logging level set? Setting a logging level means that log statements "below" that level will not be written to the output. For example, if the logging level is set to INFO and debugging statements are written with log.debug or similar, then they won't be written to the otput, which can prevent unintentional leaks of sensitive data.

Security considerations

  • We need to be explicit with whether we want to send a reset_password email to new users. This is mostly not wanted, since users should be logging in via SSO, and the default value in the provider is false

Merge request reports

Loading