Enforce password reset on api requests [Updated in Security Center 1.5]

  • リリースバージョン: Australia
  • 更新日 2026年03月12日
  • 所要時間:1分
  • Manage how the password reset functionality operates on your instance.

    When a user is marked for Password needs reset, they must provide a new password at the next authentication attempt. This property controls whether the password reset is mandatory before making API calls. If this property is not set to the recommended value of true, user accounts marked as Password needs reset can still perform operations by querying the table API through basic authentication. This security vulnerability could enable information leakage if an inactive account is compromised.

    More information

    Attribute Description
    Configuration name glide.authenticate.api.user.reset_password.mandatory
    Configuration type System Properties (/sys_properties_list.do)
    Data type Boolean
    Recommended value true
    Default value true
    Category Session management
    Security risk
    • Severity score: 8.1
    • CVSS score: High
    • Security risk details: Setting this property to false could lead to information leakage if an inactive account is compromised.
    Dependencies and prerequisites None