Comment 4 for bug 1755874

Revision history for this message
Pavlo Shchelokovskyy (pshchelo) wrote : Re: Ability to block users from changing passwords is missing in Kesystone v3

Adam, there is no more policy for that endpoint - see bug 1641645. Currently in V3 the password change does not require a token (AFAIU was done to deal with expiring passwords so that admins won't be nagged by password reset requests), thus RBAC protection is not applied.