selfservice.flows.login.style reverts to identifier_first despite explicitly setting password
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 30/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Ambito
- authentication
Direzione di ricerca
Inizia riproducendo l'aggiornamento della configurazione con kratos.config.yaml, usando ory update identity-config e ory get identity-config per confrontare lo stile di accesso richiesto con quello restituito. Verifica come interagiscono selfservice.flows.login.style, methods.code.enabled e passwordless_enabled; il lavoro è completato quando lo stile della password configurato persiste mentre il codice rimane abilitato per il recupero.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
https://busy-archimedes-8gobxuzsfx.projects.oryapis.com
Describe the bug
I am using Ory Network and trying to configure the login flow to show both the Email and Password fields immediately (single step).
I have explicitly set selfservice.flows.login.style to password in my configuration file. However, after running ory update identity-config or ory patch identity-config, the configuration either persists as identifier_first or reverts back to it immediately.
The login flow initialization continues to return group: "identifier_first" nodes, and the flow state becomes choose_method, preventing the password field from appearing in the first step.
Reproducing the bug
Identity Schema: I have updated my Identity Schema to remove all references to webauthn and passkeys. Only password is defined in ory.sh/kratos.credentials.
Configuration (kratos.config.yaml): I am trying to apply the following configuration. Note that I need code enabled for Recovery, but I have disabled it for Passwordless Login.
selfservice:
flows:
login:
style: password # <--- I want this
methods:
password:
enabled: true
code:
enabled: true # Enabled for Recovery
config:
passwordless_enabled: false # Disabled for Login to avoid identifier_first
webauthn:
enabled: false
passkey:
enabled: false
Command Execute.
ory update identity-config --project <MY_PROJECT_ID> --file kratos.config.yaml
Result: The CLI reports Project updated successfully!.
I run ory get identity-config .... Result: The output shows selfservice.flows.login.style: identifier_first. It ignores my setting.
Expected behavior
If selfservice.methods.code.config.passwordless_enabled is set to false, the system should allow selfservice.flows.login.style to be set to password, even if the code method itself is enabled globally (for recovery purposes).
Environment
$ ory version
Version: v1.2.0
Git Hash: 0e0da3c44491277d0aabeb720dc90e0c046bfc4a
Build Time: 2025-09-25T12:12:40Z
Additional context
It seems like the validation logic on Ory Network forces identifier_first as soon as it sees code.enabled: true, disregarding the passwordless_enabled: false flag or the Identity Schema structure.
Is there any hidden dependency or configuration I am missing to force the "Password" style while keeping "Code" recovery enabled?
Relevant log output
Relevant configuration
Version
v1.2.0
On which operating system are you observing this issue?
None
In which environment are you deploying?
None
Additional Context
No response
- Lingua principale
- Shell
- Stelle
- 96
- Fork
- 8
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di ory/network
-
bug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking responseApertabug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
-
Ory Account Experience (hosted UI) registration trait setup via creation of registration flowApertafeat
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
-
feat
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
-
User settings flow "back" button takes you to homepageForse di nuovo libera @jonas-jonas l’ha presa 384 giorni fa e non c’è nessuna pull request aperta. Apertabug
Issue simili
-
type: bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 67/100
catppuccin/kde#152 ·
-
update-request
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
msys2/MINGW-packages#32008 ·
I maintainer di solito rispondono entro 1 giorno
-
bot-found bug priority: P3
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
madenvel/KalinkaPlayer#179 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
I maintainer di solito rispondono entro 1 giorno
-
documentation
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100