# FM19 cancelling the expired password reset dialog LOGS YOU IN!

**URL:** <https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088>\
**Category:** Heads-Up!\
**Created:** [June 15, 2020, 7:32pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088 "2020-06-15T19:32:07Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [June 15, 2020, 7:32pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/1 "2020-06-15T19:32:07Z")

</div>

Important to know about. Read the details [here](https://community.claris.com/en/s/question/0D50H0000814f3bSAA/security-alert-filemaker-19-removes-passwords-and-hosts-open-files-on-servers-configured-to-only-host-protected-files).

Community members and Claris staff make different observations as they are attempting to reproduce the different context this can apply to.

---

<div class="post-metadata">

**Author:** ![anon45965781](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@anon45965781](https://the.fmsoup.org/u/anon45965781)\
**Post date:** [June 15, 2020, 7:46pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/2 "2020-06-15T19:46:52Z")

</div>

WOW. Thanks for posting.

(It'll be fixed in FMP 20... LOL.)

---

<div class="post-metadata">

**Author:** ![planteg](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/planteg/32/627_2.png) [@planteg](https://the.fmsoup.org/u/planteg)\
**Post date:** [June 15, 2020, 8:03pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/3 "2020-06-15T20:03:06Z")

</div>

I just can't figure out how that's possible such an issue makes its way in what was working fine before - or was it 😟 ?

Claris insists that FileMaker is very secure, that using FileMaker server is much more robust . . .

Suddenly, all my troubles seem so close to me . . . Beatles revisited .

---

<div class="post-metadata">

**Author:** ![Susurrus](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/susurrus/32/472_2.png) [@Susurrus](https://the.fmsoup.org/u/Susurrus)\
**Post date:** [June 15, 2020, 9:35pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/4 "2020-06-15T21:35:45Z")

</div>

Man I setup accounts with temp password all the time for my clients. I hope they have a fix soon.

---

<div class="post-metadata">

**Author:** ![nihm](https://avatars.discourse-cdn.com/v4/letter/n/f9ae1b/32.png) [@nihm](https://the.fmsoup.org/u/nihm)\
**Post date:** [June 15, 2020, 9:44pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/5 "2020-06-15T21:44:16Z")

</div>

Sky Willmott replied with a decent workaround (presuming you only used custom privilege sets): Set a minimum password length \> 0, and the password will not be removed when the user presses cancel.

---

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [June 15, 2020, 9:48pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/6 "2020-06-15T21:48:05Z")

</div>

@nihm thanks for sharing. This is the kind of info that is good to know in the context. Obviously, hoping that Claris will fix that soon. In the meantime, sharing ways to circumvent the problem may be the best thing we have.

---

<div class="post-metadata">

**Author:** ![Malcolm](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/malcolm/32/196_2.png) [@Malcolm](https://the.fmsoup.org/u/Malcolm)\
**Post date:** [June 15, 2020, 10:24pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/7 "2020-06-15T22:24:05Z")

</div>

Ditto. Providing a temp-password (was) a reliable and secure method that allowed the user to control the process.

---

<div class="post-metadata">

**Author:** ![planteg](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/planteg/32/627_2.png) [@planteg](https://the.fmsoup.org/u/planteg)\
**Post date:** [June 15, 2020, 10:55pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/8 "2020-06-15T22:55:44Z")

</div>

> [@Bobino](#):
>
> Obviously, hoping that Claris will fix that soon.

Hey, we will see if they can react faster and publish 20.01 now that the 'release once a year' came to an end.

---

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [June 15, 2020, 11:18pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/9 "2020-06-15T23:18:55Z")

</div>

They already said they will attempt pushing the JS things that were supposed to make the release of 19 soon. I don't know if they will put other items in there are the same time or if they will publish 2 packages back-to-back, but security related bugs should get their attention. It sure got mine.

---

<div class="post-metadata">

**Author:** ![Malcolm](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/malcolm/32/196_2.png) [@Malcolm](https://the.fmsoup.org/u/Malcolm)\
**Post date:** [June 15, 2020, 11:28pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/10 "2020-06-15T23:28:10Z")

</div>

Security fixes have always be a good enough reason for a dot point release.

---

<div class="post-metadata">

**Author:** ![steve\_ssh](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/steve_ssh/32/160_2.png) [@steve\_ssh](https://the.fmsoup.org/u/steve_ssh)\
**Post date:** [June 15, 2020, 11:38pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/11 "2020-06-15T23:38:12Z")

</div>

> [@anon45965781](#):
>
> Thanks for posting.

+1.0

---

<div class="post-metadata">

**Author:** ![anon45965781](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@anon45965781](https://the.fmsoup.org/u/anon45965781)\
**Post date:** [June 16, 2020, 9:45am UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/12 "2020-06-16T09:45:39Z")

</div>

I was wondering the same thing. Features that supposedly underwent no changes get broken from release to release? How does that happen?

---

<div class="post-metadata">

**Author:** ![WimDecorte](https://avatars.discourse-cdn.com/v4/letter/w/b19c9b/32.png) [@WimDecorte](https://the.fmsoup.org/u/WimDecorte)\
**Post date:** [June 16, 2020, 11:52am UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/13 "2020-06-16T11:52:37Z")

</div>

There really isn't a mystery around that, is there? It's in regression testing; I'm sure we've all released new versions where we introduced breakage in things that used to work just fine.

The way to catch them is to test. Now obviously the stuff we make is easier to test since we don't create a platform that is the jumping-off point for what our clients can build on it. We have a finite set of use cases / unit tests to run through. For them it is different - although this particular one should have been somewhat easy to test for.  
Claris relies on a healthy and lengthy ETS cycle to help catch these. The one for 19 was flawed with lots of start-and-stop given all the internal changes that were happening. Nobody in ETS caught this either. So if you are looking for blame or responsibility there is plenty to go around, including many of us here.

If you want to help prevent this and help make your own solutions more robust then sign up for ETS and contribute to the overall health of the platform.

---

<div class="post-metadata">

**Author:** ![anon45965781](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@anon45965781](https://the.fmsoup.org/u/anon45965781)\
**Post date:** [June 16, 2020, 1:16pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/14 "2020-06-16T13:16:56Z")

</div>

> [@WimDecorte](#):
>
> There really isn't a mystery around that, is there? It's in regression testing; I'm sure we've all released new versions where we introduced breakage in things that used to work just fine.

No, not really.

I'm thinking professional IDE.

In my case, I use JUnit and other automated testing tools that run tests each time I do a build. **If a (regression) test fails, the build fails. Period.**

> **[Testing](https://www.jenkins.io/doc/developer/testing/)**
>
> Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software

I would assume (hope?) FMI's developers would have the same type of test-build set up that's more or less automated in Maven.

Thanks,

---

<div class="post-metadata">

**Author:** ![jormond](https://avatars.discourse-cdn.com/v4/letter/j/35a633/32.png) [@jormond](https://the.fmsoup.org/u/jormond)\
**Post date:** [June 16, 2020, 1:53pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/15 "2020-06-16T13:53:49Z")

</div>

Since none of the ETS testers caught it either, and the behavior is pretty specific, I imagine the engineers will be adding a new unit-test for this piece of code. They do have a pretty impressive testing setup.

It is a little funny that you think you have not released a new version of something that didn't possibly introduce a bug on something that worked before.

---

<div class="post-metadata">

**Author:** ![anon45965781](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@anon45965781](https://the.fmsoup.org/u/anon45965781)\
**Post date:** [June 16, 2020, 2:20pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/16 "2020-06-16T14:20:29Z")

</div>

I track those things. I guess that’s why.

---

<div class="post-metadata">

**Author:** ![jormond](https://avatars.discourse-cdn.com/v4/letter/j/35a633/32.png) [@jormond](https://the.fmsoup.org/u/jormond)\
**Post date:** [June 16, 2020, 2:46pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/17 "2020-06-16T14:46:30Z")

</div>

Claris tracks them also.

---

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [June 16, 2020, 3:23pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/18 "2020-06-16T15:23:57Z")

</div>

Hi @anon45965781 I don't know how the wires are connected on the fmp login side of things, but I'm not sure I would conclude the feature underwent no changes. If I had to guess, they probably had to do some work to allow logins with Claris IDs, something akind to external authentication yes, but I'm pretty sure they did not just extend what they had for AD here.

The bottom line is there can be a gap in what we perceive and where the actual explanation may be.

Just like with anything else, I'm not looking back too much. I'm sure everyone gets to learn from this and it will minimize the chances of something similar happening going forward. I'm just glad the communication is open, we get to benefit from what another user reported and can now expect this to get the attention it deserves. I think we all look forward to that.

Like they say, it's not about how you fall, it about how you get back up. My disappointment will be greater if they fail to address this properly compared to any disappointment that can be coming from some error here or there. All that is ahead of us for now. Let's wait and see what Claris will do next.

---

<div class="post-metadata">

**Author:** ![anon45965781](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@anon45965781](https://the.fmsoup.org/u/anon45965781)\
**Post date:** [June 16, 2020, 4:25pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/19 "2020-06-16T16:25:31Z")

</div>

Fair points all. Thanks.

I've actually been very happy with FMP 19.

FMI finally fixed a long-standing "design" bug. That design bug was where they designed the debugger watch expressions to be in the volatile plist file. Then, when FMP crashed you lost all your watch expressions as the plist file regenerated. That design bug was still a problem in 16 but appears fixed now.

As I mentioned previously, the product's layout loading performance is so much improved in 19 that was almost worth the upgrade right there.

I also tried the file functions (nice to have those locally so I didn't have to code yet another micro-service method) a week ago and was also pleasantly surprised both by how easy they were to use and how fast they were. I was only outputting about a 10 MB file, but it was quick.

Thanks again for your reply.

---

<div class="post-metadata">

**Author:** ![jormond](https://avatars.discourse-cdn.com/v4/letter/j/35a633/32.png) [@jormond](https://the.fmsoup.org/u/jormond)\
**Post date:** [June 16, 2020, 4:34pm UTC](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088/20 "2020-06-16T16:34:19Z")

</div>

Keep in mind when you start dealing with data around 64 MB, there may be some unexpected behavior ( that you just need to back the writing of data in 64 MB chunks ).

[Next page](https://the.fmsoup.org/t/fm19-cancelling-the-expired-password-reset-dialog-logs-you-in/1088.md?page=2)
