You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Redirect to password change screen after login when must_change_password #92
After a successful login or token refresh, the client must check the must_change_password claim in the JWT and redirect the user to the password change screen if it is set.
Acceptance criteria
After login (POST /api/v1/auth/login) or token refresh (POST /api/v1/auth/refresh), decode the returned access token and read the must_change_password claim.
If the claim is true, navigate directly to the settings/password-change screen (see User settings page (UI) #81) instead of the home screen.
Navigation away from the password-change screen is blocked until the password has been successfully changed (claim becomes false in the next token).
The guard applies on both initial login and every token refresh so a user cannot bypass the requirement by refreshing their token.
changed the title [-]6.10 Redirect to password change screen after login when must_change_password[/-][+]Redirect to password change screen after login when must_change_password[/+]on May 12, 2026
Summary
After a successful login or token refresh, the client must check the
must_change_passwordclaim in the JWT and redirect the user to the password change screen if it is set.Acceptance criteria
POST /api/v1/auth/login) or token refresh (POST /api/v1/auth/refresh), decode the returned access token and read themust_change_passwordclaim.true, navigate directly to the settings/password-change screen (see User settings page (UI) #81) instead of the home screen.falsein the next token).Dependencies