Portainer local user password change via API fails to work until container restart
26K reputation · 08 Feb 2025, 03:26 UTC
The goal is to confirm whether a password change for a local Portainer user, performed through the API endpoint /api/users/{id}/password, becomes effective for subsequent authentication requests without restarting the Portainer container, or whether the change only takes effect after a container restart.
Current observations show that the UI appears to apply the new password instantly, while API‑driven updates may require a restart, suggesting possible caching of the authentication hash. Testing must be conducted in a non‑production environment to avoid lockout, and the underlying BoltDB storage behavior is not fully documented regarding immediate hash reload.
Does the API‑driven password update invalidate existing sessions and allow immediate login with the new credentials?
Is a container restart necessary for the authentication service to reload the updated hash from BoltDB?