Passwords and photos
How E-School issues login credentials, how users recover a forgotten password without email, and who on staff may reset whose password.
Email magic-link reset stays retired (API returns 410 Gone). Recovery is either self-service recovery codes or delegated staff reset.
What every new account receives
When Admin or Secretary creates a user, admits a learner, or adds staff, the Account credentials dialog shows once:
| Field | Purpose |
|---|---|
| School ID | Numeric school public id (e.g. 100001) for ID-based sign-in |
| User ID | Numeric user public id (e.g. 200003) - not admission number or Teacher ID |
| Temporary password | One-time password; must be changed on first login |
| Recovery codes | Eight codes in XXXX-XXXX-XXXX-XXXX form (Crockford alphabet). Store offline. Each code works once. |
Copy with Copy all (includes recovery codes) before closing. The temporary password and the current recovery-code set cannot be shown again later - only a staff reset or a successful code redeem rotates them.
First login
- Sign in at
/app/with School ID + User ID + temporary password. - Complete the forced password change.
- Optionally upload a profile photo (staff usually required; learners recommended for report cards).
- Keep the recovery-code sheet with the person who owns the account (or the parent for young learners).
See First login and Issued credentials.
Forgot password - two paths
Open Forgot password (/ecrequest). Choose a mode:
Path A - I have a recovery code (self-service)
- Select I have a recovery code.
- Enter School ID, User ID, one unused recovery code, new password, and confirm.
- On success the code is consumed, sessions are revoked, and the user signs in with the new password.
- Remaining unused codes for that account stay valid until used or until a staff reset issues a fresh set of eight.
Password rules match change-password (length, letter, digit). Wrong School/User/code combinations return a generic failure so accounts cannot be enumerated.
Path B - Ask school for help
- Select Ask school for help.
- Enter School ID + User ID and submit.
- A PENDING password-reset request is stored. Active Admin and Secretary emails for that school are notified (teachers are not mass-emailed).
- Staff fulfill the request (below), then hand the user a new temporary password and a new sheet of eight recovery codes.
Who may reset passwords (delegated reset)
Permission: system.password.reset (not full Accounts / system.user.manage).
| Actor | May reset | Where in the UI |
|---|---|---|
| ADMIN | Any active user in the same school | Staff & users / Accounts - Reset password; also Password help |
| SECRETARY | Any active school user except ADMIN | Secretary Password help (/secretary/password-help) |
| TEACHER | Only STUDENT or PARENT whose learner is in a class the teacher owns | Teacher Password help (/teacher/password-help) |
| Other roles | No | - |
Teacher class ownership (strict)
A teacher owns a class if they appear on the timetable for that class or are set as class teacher (class_teacher_staff_id).
- Empty timetable does not unlock all classes (no demo "all classes" fallback for password reset).
- STUDENT: current active enrollment class must be one of those owned classes.
- PARENT: at least one linked learner (guardian link) must be enrolled in an owned class.
After a staff reset the credentials dialog shows temporary password + fresh recovery codes (previous unused codes are rotated away).
Photos
- Staff: upload when the school requires it for directories and printouts.
- Learners: recommended so report cards show a real photo instead of gender placeholders.
Common mistakes
- Closing the credentials dialog without copying recovery codes.
- Expecting the temporary password to be recoverable later without a reset or a recovery code.
- Giving Teacher ID / admission number instead of User ID.
- Secretary trying to reset an ADMIN (denied).
- Teacher expecting to reset colleagues or learners outside their classes (denied).
- Using an old email reset link - use a recovery code or ask the school office.
- Losing the recovery sheet - ask Admin/Secretary/class teacher for a staff reset.