Skip to content

fix: Start-TssSecretChangePassword defaults -Type to 'Random' (#444) - #471

Merged
jagger merged 1 commit into
devfrom
jagger/fix-444-changepassword-default-random
Jun 30, 2026
Merged

jagger merged 1 commit into
devfrom
jagger/fix-444-changepassword-default-random

Conversation

@jagger

@jagger jagger commented Jun 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Removes [Parameter(Mandatory)] from -Type and sets its default to 'Random'. The most common call - an immediate random password rotation - is now:

Start-TssSecretChangePassword -TssSession $s -Id 46

instead of the previously required -Type Random boilerplate.

Adds a second .EXAMPLE showing the Manual-with-supplied-password path so the non-default usage is still easy to find.

Closes #444.

Behavior matrix

Unchanged from what the issue requested:

-Type -NextPassword Result
(omitted) (omitted) Random rotation (new default)
Random (omitted) Random rotation (explicit, same as before)
Manual provided Manual rotation
Manual (omitted) Error: -NextPassword required (unchanged)
Random provided Error: -NextPassword cannot be used with Random (unchanged)

Lab verification

Against Secret Server 12.x:

=== Call without -Type (should default to Random) ===
POST .../internals/secret-detail/86509/change-password-now with:
  { "data": { "PasswordType": 0, "NextPassword": null } }
Password Change successfully started on Secret [86509]

=== Call with -Type Manual but no -NextPassword (should error gracefully) ===
-NextPassword parameter must be provided when using PasswordType of [Manual]

Both paths behave as specified.

Release

Targets v0.62.1 (on the 0.62.1 milestone). UX change with no API surface removal - callers who were explicitly passing -Type Random continue to work identically.

🤖 Generated with Claude Code

Removes [Parameter(Mandatory)] from -Type and sets the default value to
'Random'. The most common usage (an immediate random rotation) is now:

  Start-TssSecretChangePassword -TssSession $s -Id 46

instead of the previously required:

  Start-TssSecretChangePassword -TssSession $s -Id 46 -Type Random

Behavior matrix is unchanged from what the issue specified:

  -Type omitted, -NextPassword omitted     -> Random rotation (new default)
  -Type Random, -NextPassword omitted      -> Random rotation (explicit)
  -Type Manual, -NextPassword provided     -> Manual rotation
  -Type Manual, -NextPassword omitted      -> Error (unchanged)
  -Type Random, -NextPassword provided     -> Error (unchanged)

Adds a second .EXAMPLE showing the Manual case so callers can find the
non-default path easily.

Verified against Secret Server 12.x lab: a no -Type call against a
freshly-created AD secret successfully started a random rotation
(PasswordType: 0, NextPassword: null in the request body).

Closes #444.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@jagger
jagger force-pushed the jagger/fix-444-changepassword-default-random branch from de0555a to d982886 Compare June 30, 2026 21:04
@jagger
jagger merged commit e7dabd8 into dev Jun 30, 2026
4 checks passed
@jagger
jagger deleted the jagger/fix-444-changepassword-default-random branch June 30, 2026 21:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Start-TssSecretChangePassword: Default -Type parameter to 'Random' when not specified

1 participant