You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2IS v5.11 askPassword功能用户创建时accountLocked属性未锁定问题咨询

Great question! Let's break this down clearly for you:

Is this behavior normal?

Absolutely—this is expected default behavior in WSO2 Identity Server v5.11, driven by the distinct design goals of the two features:

  • askPassword: true: This workflow is built to prompt users to set/reset their password on their first login, but the account remains accessible. That’s why accountLocked stays false and accountState is set to PENDING_AP—users can initiate the login flow right away, and only need to complete the password reset step to transition to the UNLOCKED state.
  • verifyEmail: true: This workflow requires users to verify their email address before gaining any access to the account. To enforce this mandatory check, the account is automatically locked (accountLocked: true) by default. It only unlocks once the user completes the email verification process.
Can you configure WSO2IS to set accountLocked: true when askPassword: true?

There’s no out-of-the-box configuration toggle for this, but you can achieve this with custom extensions. Here are a few reliable approaches:

  • Custom Identity Event Listener:
    Build an OSGi bundle that implements the org.wso2.carbon.user.core.listener.UserOperationEventListener interface. Override either doPreAddUser or doPostAddUser to check if the askPassword extension attribute is set to true. If it is, explicitly set the accountLocked attribute to true during user creation, then deploy this bundle to your WSO2IS instance.
  • Custom SCIM Resource Handler:
    Extend the default SCIM User Resource Handler (org.wso2.carbon.identity.scim2.common.handlers.UserResourceHandler) and modify the user creation logic. Whenever askPassword is enabled in the incoming SCIM payload, add logic to set accountLocked: true. Then register your custom handler in the SCIM configuration files.
  • Script Mediator in SCIM API Flow:
    If you’re mediating SCIM requests (e.g., via WSO2 API Manager or custom mediation sequences), add a script mediator that intercepts user creation requests. When askPassword: true is detected in the payload, inject the accountLocked: true attribute before the request is processed by the user store.

A quick note: When combining accountLocked: true with askPassword: true, be sure to test the end-to-end flow. You’ll want to ensure users can still initiate the password reset process to unlock their account—you might need to adjust authentication flows to allow password reset for locked accounts with the PENDING_AP state.

内容的提问来源于stack exchange,提问作者Артём Власов

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 15:47:34