WSO2IS v5.11 askPassword功能用户创建时accountLocked属性未锁定问题咨询
Great question! Let's break this down clearly for you:
Absolutely—this is expected default behavior in WSO2 Identity Server v5.11, driven by the distinct design goals of the two features:
askPassword: true: This workflow is built to prompt users to set/reset their password on their first login, but the account remains accessible. That’s whyaccountLockedstaysfalseandaccountStateis set toPENDING_AP—users can initiate the login flow right away, and only need to complete the password reset step to transition to theUNLOCKEDstate.verifyEmail: true: This workflow requires users to verify their email address before gaining any access to the account. To enforce this mandatory check, the account is automatically locked (accountLocked: true) by default. It only unlocks once the user completes the email verification process.
accountLocked: true when askPassword: true? There’s no out-of-the-box configuration toggle for this, but you can achieve this with custom extensions. Here are a few reliable approaches:
- Custom Identity Event Listener:
Build an OSGi bundle that implements theorg.wso2.carbon.user.core.listener.UserOperationEventListenerinterface. Override eitherdoPreAddUserordoPostAddUserto check if theaskPasswordextension attribute is set totrue. If it is, explicitly set theaccountLockedattribute totrueduring user creation, then deploy this bundle to your WSO2IS instance. - Custom SCIM Resource Handler:
Extend the default SCIM User Resource Handler (org.wso2.carbon.identity.scim2.common.handlers.UserResourceHandler) and modify the user creation logic. WheneveraskPasswordis enabled in the incoming SCIM payload, add logic to setaccountLocked: true. Then register your custom handler in the SCIM configuration files. - Script Mediator in SCIM API Flow:
If you’re mediating SCIM requests (e.g., via WSO2 API Manager or custom mediation sequences), add a script mediator that intercepts user creation requests. WhenaskPassword: trueis detected in the payload, inject theaccountLocked: trueattribute before the request is processed by the user store.
A quick note: When combining accountLocked: true with askPassword: true, be sure to test the end-to-end flow. You’ll want to ensure users can still initiate the password reset process to unlock their account—you might need to adjust authentication flows to allow password reset for locked accounts with the PENDING_AP state.
内容的提问来源于stack exchange,提问作者Артём Власов

