none
Forgot Password link not working for the Azure B2C AD RRS feed

  • Question

  • Dear All, 

    I would like to know How the change password link is working, I have configured both asp.net core application with Azure b2c as well as the moodle (LMS) open source with Azure b2c. 

     1. asp.net core web application it works fine and the Password reset and profile edit policies are mentioned in the config file. 

     2. Moodle LMS we have modified the custom code changes and now the sign in and sign up is working as expected but the forgot password link is not working.  

    below in the URL captured when try to login for the moodle LMS system

    https://b2ctest.b2clogin.com/b2cTest.onmicrosoft.com/B2C_1_signinupmoodle/api/CombinedSigninAndSignup/forgotPassword?csrf_token=SgsdgsgsdfmdfgdfgdfWDfgfdgfdgfdycXkvZUR5sdfsA4LTE0VDEwOjA0OjE2LjA4MzQxNFo7S2pOaUtlVk95WFdkY0FRclZpOWpmdz09O3siT3JjaGVzdHJhdGlvblN0ZXAiOjF9&

    tx=StateProperties=eyJUSUQiOiI2ZTUxZmY0My1lN2I5LTQ5N2EtYTFkMi00YzgxNTFiZDBjNGUifQ&p=B2C_1_signinupmoodle

    When trying to login both the application the forgot password link is appropriate to that application's policies.

    But not sure how it is working for the asp.net core application and not working for PHP application.  Requesting the expert to answer this question. 


    Selvakumar Rathinam

    Wednesday, August 14, 2019 10:23 AM

Answers

  • Thanks for your response. 

    I have handled it in the Moodle LMS application itself based on the error code thrown AADB2C90118: The user has forgotten their password.

    we are redirecting to the password policy link and it works as expected. 

     


    Selvakumar Rathinam

    Friday, August 16, 2019 7:50 AM

All replies

  • Hey Selvakumar,

    Could you provide the error that you're getting when trying to login with the Moodle LMS system?

    Are you following a document on how to set this up? 

    Also, is there any way to get a fiddler trace on the Moodle LMS system of the error occurring? 

    Perhaps a steps recorder of the login from Moodle LMS would be good as well.

    We'll need to get some more info in regards to this to try to progress forwards. 

    I'll also look into this and do some more research and see if I can figure out if there are any compatibility issues there could be with b2c forgot password flow and moodle LMS. 

    The official docs on this can be found here : https://docs.microsoft.com/en-us/azure/active-directory-b2c/active-directory-b2c-reference-sspr

    Are you sure that the accounts that they're using are local accounts? Per the b2c doc it says that is a requirement for the forgot password v1 sign in user flow. If you require a more custom password reset flow you'll need a more custom policy, and then the note refers to the link : https://docs.microsoft.com/en-us/azure/active-directory-b2c/active-directory-b2c-reference-policies

    Thanks,

    - Frank Hu

    Wednesday, August 14, 2019 10:49 PM
    Moderator
  • Thanks for your response. 

    I have handled it in the Moodle LMS application itself based on the error code thrown AADB2C90118: The user has forgotten their password.

    we are redirecting to the password policy link and it works as expected. 

     


    Selvakumar Rathinam

    Friday, August 16, 2019 7:50 AM