Update Javadoc for UserDetailsManager to reflect that the new password doesn't need to be stored in the security context (and probably shouldn't be).
This commit is contained in:
+1
-2
@@ -29,8 +29,7 @@ public interface UserDetailsManager extends UserDetailsService {
|
||||
|
||||
/**
|
||||
* Modify the current user's password. This should change the user's password in
|
||||
* the persistent user repository (datbase, LDAP etc) and should also modify the
|
||||
* current security context to contain the new password.
|
||||
* the persistent user repository (datbase, LDAP etc).
|
||||
*
|
||||
* @param oldPassword current password (for re-authentication if required)
|
||||
* @param newPassword the password to change to
|
||||
|
||||
Reference in New Issue
Block a user