Skip to content

Redirect to password change screen after login when must_change_password #92

Description

@bitbiter-dev

Summary

After a successful login or token refresh, the client must check the must_change_password claim in the JWT and redirect the user to the password change screen if it is set.

Acceptance criteria

  • After login (POST /api/v1/auth/login) or token refresh (POST /api/v1/auth/refresh), decode the returned access token and read the must_change_password claim.
  • If the claim is true, navigate directly to the settings/password-change screen (see User settings page (UI) #81) instead of the home screen.
  • Navigation away from the password-change screen is blocked until the password has been successfully changed (claim becomes false in the next token).
  • The guard applies on both initial login and every token refresh so a user cannot bypass the requirement by refreshing their token.

Dependencies

Activity

  1. changed the title [-]6.10 Redirect to password change screen after login when must_change_password[/-] [+]Redirect to password change screen after login when must_change_password[/+] on May 12, 2026
  2. modified the milestones: Epic 6: Flashback UI — Core Experience, , Epic 6: Admin UI on May 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-humanRequires human implementationv1.0Required for the v1.0 release

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions