LDAP Tool Box Self Service Password 1.6.0

The LDAP Tool Box project provides a set of LDAP-related applications, administrative tools, and other utilities. They have just released version 1.6.0 of their Self Service Password tool, which is a PHP application that allows users to change their password in an LDAP directory. Changes in this release include:

  • Added audit logging support
  • Added the ability to use a login hint to pre-fill the username field
  • Added a page to set email and phone number attributes
  • Added support for filtering allowed languages
  • Improved security and error handling when using SMS
  • Prevented multiple submits of the same form
  • Removed criteria that depends on a former password when that password is not available
  • Improved translations
  • Added a change to prevent host header poisoning
  • Improved the logic used to determine the difference between former and new passwords
  • Added the ability to change custom password fields