Project

General

Profile

Actions

Regression #16728

closed

Changing the password from the default in the GUI from the default requires a logout and login to continue

Added by Christopher Cope about 1 month ago. Updated about 1 month ago.

Status:
Resolved
Priority:
Normal
Category:
Authentication
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
26.03
Release Notes:
Force Exclusion
Affected Version:
2.9.0
Affected Architecture:

Description

Tested on

26.07-DEVELOPMENT (amd64)
built on Fri Feb 27 6:00:00 UTC 2026
FreeBSD 16.0-CURRENT

During the first login it requests to change the password from the default. After doing that, any attempts to navigate just redirect back to the same page /system_usermanager_passwordmg.php asking to change the password.

Changing the password from the console before logging in doesn't cause any issues, but if I login and then change it from the console I end up in the same loop.

I have to logout and back in to get it to recognize that the password has been changed. It seems it only recognizes if the password is default or not at login and stays in that state.

I thought it might have been due to https://redmine.pfsense.org/issues/16720, but reverting those changes doesn't appear to change it.

Actions #1

Updated by Danilo Zrenjanin about 1 month ago

  • Status changed from New to Confirmed

I was able to reproduce the same behavior on the same software version.

Steps to Reproduce:

  1. Reset the device to factory defaults.
  2. Log in for the first time.
  3. Skip the initial setup wizard.
  4. Navigate directly to System > User Password Manager > Change Password.
  5. Enter and apply a new password.

After changing the password, navigation to any other page is no longer possible. The GUI continuously redirects back to the Change Password page, preventing access to the rest of the interface.

Actions #2

Updated by Christian McDonald about 1 month ago

  • Assignee set to Christian McDonald
  • Target version set to CE-Next
  • Plus Target Version set to 26.03
  • Release Notes changed from Default to Force Exclusion

It is likely some fallout from #16720. I'll get it fixed.

Actions #3

Updated by Christian McDonald about 1 month ago

  • Status changed from Confirmed to Feedback
  • % Done changed from 0 to 100

Applied in changeset commit:aee3be62002db0481b9f60add522b3d00d58472e

Actions #4

Updated by Marcos M about 1 month ago

  • Tracker changed from Bug to Regression
  • Project changed from pfSense to pfSense Plus
  • Category changed from Authentication to Authentication
  • Target version changed from CE-Next to 26.03
  • Plus Target Version deleted (26.03)
  • Affected Plus Version set to 26.03
Actions #5

Updated by Jim Pingle about 1 month ago

  • Project changed from pfSense Plus to pfSense
  • Category changed from Authentication to Authentication
  • Target version changed from 26.03 to 2.9.0
  • Affected Plus Version deleted (26.03)
  • Plus Target Version set to 26.03
Actions #6

Updated by Marcos M about 1 month ago

  • Status changed from Feedback to Resolved
  • Affected Version set to 2.9.0

Unable to replicate issue with the latest patch applied.

Actions

Also available in: Atom PDF