selfservice.flows.login.style reverts to identifier_first despite explicitly setting password
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 30/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
调研方向
首先使用 kratos.config.yaml 重现配置更新,并使用 ory update identity-config 和 ory get identity-config 比较请求的登录样式与返回的登录样式。验证 selfservice.flows.login.style、methods.code.enabled 和 passwordless_enabled 如何相互作用;当配置的密码样式保持不变,同时代码仍为恢复功能启用时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
https://busy-archimedes-8gobxuzsfx.projects.oryapis.com
Describe the bug
I am using Ory Network and trying to configure the login flow to show both the Email and Password fields immediately (single step).
I have explicitly set selfservice.flows.login.style to password in my configuration file. However, after running ory update identity-config or ory patch identity-config, the configuration either persists as identifier_first or reverts back to it immediately.
The login flow initialization continues to return group: "identifier_first" nodes, and the flow state becomes choose_method, preventing the password field from appearing in the first step.
Reproducing the bug
Identity Schema: I have updated my Identity Schema to remove all references to webauthn and passkeys. Only password is defined in ory.sh/kratos.credentials.
Configuration (kratos.config.yaml): I am trying to apply the following configuration. Note that I need code enabled for Recovery, but I have disabled it for Passwordless Login.
selfservice:
flows:
login:
style: password # <--- I want this
methods:
password:
enabled: true
code:
enabled: true # Enabled for Recovery
config:
passwordless_enabled: false # Disabled for Login to avoid identifier_first
webauthn:
enabled: false
passkey:
enabled: false
Command Execute.
ory update identity-config --project <MY_PROJECT_ID> --file kratos.config.yaml
Result: The CLI reports Project updated successfully!.
I run ory get identity-config .... Result: The output shows selfservice.flows.login.style: identifier_first. It ignores my setting.
Expected behavior
If selfservice.methods.code.config.passwordless_enabled is set to false, the system should allow selfservice.flows.login.style to be set to password, even if the code method itself is enabled globally (for recovery purposes).
Environment
$ ory version
Version: v1.2.0
Git Hash: 0e0da3c44491277d0aabeb720dc90e0c046bfc4a
Build Time: 2025-09-25T12:12:40Z
Additional context
It seems like the validation logic on Ory Network forces identifier_first as soon as it sees code.enabled: true, disregarding the passwordless_enabled: false flag or the Identity Schema structure.
Is there any hidden dependency or configuration I am missing to force the "Password" style while keeping "Code" recovery enabled?
Relevant log output
Relevant configuration
Version
v1.2.0
On which operating system are you observing this issue?
None
In which environment are you deploying?
None
Additional Context
No response
- 主要语言
- Shell
- 星标
- 96
- 派生
- 8
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
ory/network 的其他 Issue
-
bug
难度 4/5 3-5 天 新手友好度 38/100
-
Updating native registration flow with OIDC ID token for existing identity returns breaking response未关闭bug
难度 4/5 3-5 天 新手友好度 35/100
-
feat
难度 5/5 一周以上 新手友好度 25/100
-
feat
难度 5/5 一周以上 新手友好度 35/100
-
User settings flow "back" button takes you to homepage可能重新可做 @jonas-jonas 于 384 天前认领,目前没有进行中的 PR。 未关闭bug
相似的 Issue
-
type: bug
难度 2/5 1-3 小时 新手友好度 67/100
catppuccin/kde#152 ·
-
update-request
难度 2/5 1-3 小时 新手友好度 75/100
msys2/MINGW-packages#32008 ·
维护者通常 1 天内回复
-
bot-found bug priority: P3
难度 2/5 1-3 小时 新手友好度 84/100
madenvel/KalinkaPlayer#179 ·
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
documentation
难度 2/5 1-3 小时 新手友好度 72/100