Skip to content

Fix admin password change for AEMaaCS/Cloud SDK - #7

Merged
tobias-richter merged 6 commits into
masterfrom
feature/fix-set-admin-password-aemaacs
Sep 14, 2026
Merged

tobias-richter merged 6 commits into
masterfrom
feature/fix-set-admin-password-aemaacs

Conversation

@tobias-richter

Copy link
Copy Markdown
Contributor

Problem

/crx/explorer/ui/setpassword.jsp is JSP-based and no longer functional on AEMaaCS/Cloud SDK instances (throws a JspFactory.getJspApplicationContext(...) NPE), so the Set new password task fails there.

Fix

  • Resolve the admin user's JCR path (already done via aem_security_url_userinfo).
  • POST rep:password=<new password> directly to that JCR node via the standard Sling default POST servlet, instead of the JSP endpoint. Oak/Jackrabbit intercepts writes to the protected rep:password property and hashes it correctly. Verified working against both classic AEM and an AEMaaCS/Cloud SDK instance.
  • Apache Sling's UserManager :operation=changePassword servlet was also considered, but that bundle isn't shipped on AEMaaCS/Cloud SDK, so it's not a viable alternative.
  • Added an explicit post-change verification step (authenticate with the new password) since the POST response no longer reliably reflects whether the write succeeded.
  • Removed the now-unused aem_security_url_password_set default and updated the README.

/crx/explorer/ui/setpassword.jsp is JSP-based and no longer functional on
AEMaaCS/Cloud SDK (JspFactory NPE). Apache Sling's UserManager
:operation=changePassword servlet is also unavailable there (bundle not
shipped).

Instead, POST rep:password directly to the user's JCR node via the
standard Sling default POST servlet, which works on both classic AEM
6.5/6.5 LTS and AEMaaCS/Cloud SDK. Since the POST response no longer
reliably indicates success, verify the change by authenticating with the
new password afterward.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Raw passwords can be altered when special characters are submitted without form encoding.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Updates admin password changes to use a direct JCR POST compatible with classic AEM and AEMaaCS/Cloud SDK.

Changes:

  • Replaces the JSP endpoint with a Sling POST and adds authentication verification.
  • Removes the obsolete password-set URL default.
  • Updates the README documentation.
File summaries
File Reviewed changes Findings
tasks/set-admin-password.yml Direct password update and verification Moderate: form-urlencoded passwords must be encoded to preserve special characters.
README.md Documents the updated password workflow None
defaults/main.yml Removes the obsolete endpoint default None
Review details
  • Files reviewed: 4/4 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tasks/set-admin-password.yml Outdated
- Use FQCN for uri/include_tasks module actions
- Quote galaxy_info.min_ansible_version as a string
- Set EL platform versions to a valid schema value
- Move Jinja templates to the end of task names
- Name the previously anonymous block and fix its key order
- Use a YAML list for status_code instead of a comma-joined string
- Fix name casing in tests/test.yml
FQCN module references (ansible.builtin.uri, ansible.builtin.include_tasks)
require ansible-core 2.10+; align meta/README/CI min-version matrix with
that requirement.
Use uri's body_format: form-urlencoded with a dict body instead of
manually interpolating the password into a raw query string, so
passwords containing &, =, +, or % are transmitted correctly instead
of being corrupted/truncated.
@tobias-richter
tobias-richter merged commit e41daf5 into master Sep 14, 2026
3 checks passed
@tobias-richter
tobias-richter deleted the feature/fix-set-admin-password-aemaacs branch September 14, 2026 19:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants