[keycloak-user] password history not always correctly considered

Bystrik Horvath bystrik.horvath at gmail.com
Tue Oct 25 07:23:46 EDT 2016


Hello,

I have a realm where password history was set to 3. When I try to set the
password for an user too fast (via REST API), I'm able to use one of the
passwords that should be recorded as not usable. When I put a small sleep
between the password changes (aprox. 300 ms), the usecase works fine - so
I'm not allowed to use any of the 3 recorded password from the history. I
tested the case using 1.9.3 Final and 2.2.1 Final with same results.
It looks to me like a bug, isn't it?

Thank you for the answer&best regards,
Bystrik


More information about the keycloak-user mailing list