Send Password Reset Link Block
Purpose: Provides (in some circumstances) a button that will email a user a password reset link good for one use within 24 hours.
Cost: None.
User Experience
The user will get an email from "no-reply@yoursite.legalserver.org" with the subject "LegalServer Password Reset".
- They click the link in the email and will be taken to the site to create a new password.
- As soon as they create their new password, they will be logged out to ensure they know both their new password and username.
- If they must enable MFA (Multifactor Authentication), that will happen on the new login.
Setup
The block is designed to be put on a dynamic user module auxiliary form. The process calling this form is typically limited to the Administrator user role, and possibly other select roles.
The block can also be used on a dynamic user profile page to provide a clickable link to the dynamic process. But, as recommended above, that should result in a permission denied page for most users.
NB: The block will not allow sending a reset link to a user if their role has any of the following permissions:
- API Access
- Administer User Passwords
- Edit System Settings
The block will display a message for each permission that prevents sending a link. And of course it will not allow sending a link to a user who does not have an email address in their contact information.
If you have an email link scanning tool that opens links to make sure that the link is not malicious, this feature may not work. We try to account for this, but the scanner may use the one available use of the link.
Need help adding a new process and form to your dynamic User records? See: Step by Step - Adding an Actions menu Link and Form to Cases or Other Records.