modX Revo password expiry and least-privilege authentication transition
0 reputation · 23 Sept 2021, 23:08 UTC
Implementing a least-privilege security model in modX Revo involves utilizing Access Policies and User Groups to restrict modUser permissions. While granular resource access is well-documented, the enforcement of credential lifecycles remains inconsistent across different environment configurations.
The login_password_expiry system setting allows administrators to define a numeric day interval for password rotation. However, the interaction between this setting and custom authentication plugins can create uncertainty regarding whether the expiry prompt is consistently triggered before the user gains access to their assigned context.
Given the balance between security hardening and user experience, what is the expected behavior when a user with highly restricted permissions hits the expiry threshold? Does the core authentication flow prioritize the password change prompt over the restricted access policy, or can a least-privilege configuration inadvertently bypass the expiry notification?