Fix admin password change for AEMaaCS/Cloud SDK - #7
Merged
Merged
Conversation
/crx/explorer/ui/setpassword.jsp is JSP-based and no longer functional on AEMaaCS/Cloud SDK (JspFactory NPE). Apache Sling's UserManager :operation=changePassword servlet is also unavailable there (bundle not shipped). Instead, POST rep:password directly to the user's JCR node via the standard Sling default POST servlet, which works on both classic AEM 6.5/6.5 LTS and AEMaaCS/Cloud SDK. Since the POST response no longer reliably indicates success, verify the change by authenticating with the new password afterward.
There was a problem hiding this comment.
🟡 Changes recommended
Raw passwords can be altered when special characters are submitted without form encoding.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Updates admin password changes to use a direct JCR POST compatible with classic AEM and AEMaaCS/Cloud SDK.
Changes:
- Replaces the JSP endpoint with a Sling POST and adds authentication verification.
- Removes the obsolete password-set URL default.
- Updates the README documentation.
File summaries
| File | Reviewed changes | Findings |
|---|---|---|
tasks/set-admin-password.yml |
Direct password update and verification | Moderate: form-urlencoded passwords must be encoded to preserve special characters. |
README.md |
Documents the updated password workflow | None |
defaults/main.yml |
Removes the obsolete endpoint default | None |
Review details
- Files reviewed: 4/4 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Use FQCN for uri/include_tasks module actions - Quote galaxy_info.min_ansible_version as a string - Set EL platform versions to a valid schema value - Move Jinja templates to the end of task names - Name the previously anonymous block and fix its key order - Use a YAML list for status_code instead of a comma-joined string - Fix name casing in tests/test.yml
FQCN module references (ansible.builtin.uri, ansible.builtin.include_tasks) require ansible-core 2.10+; align meta/README/CI min-version matrix with that requirement.
Use uri's body_format: form-urlencoded with a dict body instead of manually interpolating the password into a raw query string, so passwords containing &, =, +, or % are transmitted correctly instead of being corrupted/truncated.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
/crx/explorer/ui/setpassword.jspis JSP-based and no longer functional on AEMaaCS/Cloud SDK instances (throws aJspFactory.getJspApplicationContext(...)NPE), so theSet new passwordtask fails there.Fix
aem_security_url_userinfo).rep:password=<new password>directly to that JCR node via the standard Sling default POST servlet, instead of the JSP endpoint. Oak/Jackrabbit intercepts writes to the protectedrep:passwordproperty and hashes it correctly. Verified working against both classic AEM and an AEMaaCS/Cloud SDK instance.:operation=changePasswordservlet was also considered, but that bundle isn't shipped on AEMaaCS/Cloud SDK, so it's not a viable alternative.aem_security_url_password_setdefault and updated the README.