Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

selfservice.flows.login.style reverts to identifier_first despite explicitly setting password

オープン
#441 コメント 3 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
30/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
停滞

調査の方向性

まず、kratos.config.yaml を使って設定の更新を再現し、ory update identity-config と ory get identity-config を使用して、要求したログインスタイルと返されたログインスタイルを比較します。selfservice.flows.login.style、methods.code.enabled、passwordless_enabled がどのように相互作用するかを確認します。設定したパスワードスタイルが維持され、復旧用のコードが有効なままであれば完了です。

索引モデルが issue の本文から書いたものです。

説明

bug
Preflight checklist
Ory Network Project

https://busy-archimedes-8gobxuzsfx.projects.oryapis.com

Describe the bug

I am using Ory Network and trying to configure the login flow to show both the Email and Password fields immediately (single step).

I have explicitly set selfservice.flows.login.style to password in my configuration file. However, after running ory update identity-config or ory patch identity-config, the configuration either persists as identifier_first or reverts back to it immediately.

The login flow initialization continues to return group: "identifier_first" nodes, and the flow state becomes choose_method, preventing the password field from appearing in the first step.

Reproducing the bug

Identity Schema: I have updated my Identity Schema to remove all references to webauthn and passkeys. Only password is defined in ory.sh/kratos.credentials.

Configuration (kratos.config.yaml): I am trying to apply the following configuration. Note that I need code enabled for Recovery, but I have disabled it for Passwordless Login.

selfservice:
  flows:
    login:
      style: password  # <--- I want this
  methods:
    password:
      enabled: true
    code:
      enabled: true    # Enabled for Recovery
      config:
        passwordless_enabled: false # Disabled for Login to avoid identifier_first
    webauthn:
      enabled: false
    passkey:
      enabled: false

Command Execute.

ory update identity-config --project <MY_PROJECT_ID> --file kratos.config.yaml

Result: The CLI reports Project updated successfully!.

I run ory get identity-config .... Result: The output shows selfservice.flows.login.style: identifier_first. It ignores my setting.

Expected behavior

If selfservice.methods.code.config.passwordless_enabled is set to false, the system should allow selfservice.flows.login.style to be set to password, even if the code method itself is enabled globally (for recovery purposes).

Environment

$ ory version
Version:    v1.2.0
Git Hash:   0e0da3c44491277d0aabeb720dc90e0c046bfc4a
Build Time: 2025-09-25T12:12:40Z

Additional context

It seems like the validation logic on Ory Network forces identifier_first as soon as it sees code.enabled: true, disregarding the passwordless_enabled: false flag or the Identity Schema structure.

Is there any hidden dependency or configuration I am missing to force the "Password" style while keeping "Code" recovery enabled?

Relevant log output

Relevant configuration

Version

v1.2.0

On which operating system are you observing this issue?

None

In which environment are you deploying?

None

Additional Context

No response

主要言語
Shell
スター
96
フォーク
8
PR マージ指標
30日以内にマージされた PR はありません

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

ory/network のほかの issue

ory/network の issue をすべて見る

似ている issue

Shell/Bash の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。