Component
User Management
Priority
Medium - Would improve workflow
Problem Description
The current workflow involves the admin user creating a user account and assigning an initial password. There is no option for the user to change their password. We currently do not enforce minimum requirements for passwords either and the email fields in the Add New User part of the Admin tab does not require validation. All of this needs improving.
Proposed Solution
- Implement a 'Change Password' feature once the user is logged in.
- If the user is logging in for the first time, prompt to change password and do not continue until the password is changed.
- Enforce minimum password requirements - Minimum 8 characters, one capital, one number and one non-alphanumeric character
- Add a repeat password box at both user creation time by the admin and the user's own change password workflow.
Alternative Solutions
Leave things as they are now. This is not ideal.
User Story
As a non-administrative user, I want to be able to change the password to something that I can remember and something that is different from what was set up by the admin. This will improve security.
As a admin user, I want the user to be able to change their password. I want to enforce minimum password requirements and password validation to avoid mistypes. I want email field to be validated as well. Email should end with nhs.uk.
Acceptance Criteria
Mockups/Wireframes
No response
User Type
All Users
Current Workflow
No response
Impact Assessment
No response
Technical Considerations
This is important part of improving the security of the overall solution.
Additional Context
No response
Checklist
Component
User Management
Priority
Medium - Would improve workflow
Problem Description
The current workflow involves the admin user creating a user account and assigning an initial password. There is no option for the user to change their password. We currently do not enforce minimum requirements for passwords either and the email fields in the Add New User part of the Admin tab does not require validation. All of this needs improving.
Proposed Solution
Alternative Solutions
Leave things as they are now. This is not ideal.
User Story
As a non-administrative user, I want to be able to change the password to something that I can remember and something that is different from what was set up by the admin. This will improve security.
As a admin user, I want the user to be able to change their password. I want to enforce minimum password requirements and password validation to avoid mistypes. I want email field to be validated as well. Email should end with nhs.uk.
Acceptance Criteria
Mockups/Wireframes
No response
User Type
All Users
Current Workflow
No response
Impact Assessment
No response
Technical Considerations
This is important part of improving the security of the overall solution.
Additional Context
No response
Checklist