Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

selfservice.flows.login.style reverts to identifier_first despite explicitly setting password

未关闭
#441 3 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
30/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
停滞

调研方向

首先使用 kratos.config.yaml 重现配置更新,并使用 ory update identity-config 和 ory get identity-config 比较请求的登录样式与返回的登录样式。验证 selfservice.flows.login.style、methods.code.enabled 和 passwordless_enabled 如何相互作用;当配置的密码样式保持不变,同时代码仍为恢复功能启用时,即表示完成。

由索引模型根据 Issue 内容生成。

描述

bug
Preflight checklist
Ory Network Project

https://busy-archimedes-8gobxuzsfx.projects.oryapis.com

Describe the bug

I am using Ory Network and trying to configure the login flow to show both the Email and Password fields immediately (single step).

I have explicitly set selfservice.flows.login.style to password in my configuration file. However, after running ory update identity-config or ory patch identity-config, the configuration either persists as identifier_first or reverts back to it immediately.

The login flow initialization continues to return group: "identifier_first" nodes, and the flow state becomes choose_method, preventing the password field from appearing in the first step.

Reproducing the bug

Identity Schema: I have updated my Identity Schema to remove all references to webauthn and passkeys. Only password is defined in ory.sh/kratos.credentials.

Configuration (kratos.config.yaml): I am trying to apply the following configuration. Note that I need code enabled for Recovery, but I have disabled it for Passwordless Login.

selfservice:
  flows:
    login:
      style: password  # <--- I want this
  methods:
    password:
      enabled: true
    code:
      enabled: true    # Enabled for Recovery
      config:
        passwordless_enabled: false # Disabled for Login to avoid identifier_first
    webauthn:
      enabled: false
    passkey:
      enabled: false

Command Execute.

ory update identity-config --project <MY_PROJECT_ID> --file kratos.config.yaml

Result: The CLI reports Project updated successfully!.

I run ory get identity-config .... Result: The output shows selfservice.flows.login.style: identifier_first. It ignores my setting.

Expected behavior

If selfservice.methods.code.config.passwordless_enabled is set to false, the system should allow selfservice.flows.login.style to be set to password, even if the code method itself is enabled globally (for recovery purposes).

Environment

$ ory version
Version:    v1.2.0
Git Hash:   0e0da3c44491277d0aabeb720dc90e0c046bfc4a
Build Time: 2025-09-25T12:12:40Z

Additional context

It seems like the validation logic on Ory Network forces identifier_first as soon as it sees code.enabled: true, disregarding the passwordless_enabled: false flag or the Identity Schema structure.

Is there any hidden dependency or configuration I am missing to force the "Password" style while keeping "Code" recovery enabled?

Relevant log output

Relevant configuration

Version

v1.2.0

On which operating system are you observing this issue?

None

In which environment are you deploying?

None

Additional Context

No response

主要语言
Shell
星标
96
派生
8
PR 合并指标
30 天内没有已合并 PR

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

ory/network 的其他 Issue

查看 ory/network 的全部 Issue

相似的 Issue

更多 Shell/Bash Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。