We're looking at possibly moving certain authentication systems to Crowd. One issue that we've come upon is the user password reset feature.
While this is very useful, our security policy requires administrator approval of password resets.
Ideally, we'd like to forward password reset mail to the administrator to relay to the end-user. I can certainly think of ways to hack around this once a request hits the Crowd host's mail server, but I'm wondering whether there's another somewhat more "regular" approach.
If we can't do this, then we would like to figure out a way to just remove the functionality from the UI if possible. It would be nice to keep the "reset" function that's implemented in the administrator UI (generating a random URL) - that might be helpful. But if someone's email account gets hacked, we need to limit exposure there (not to mention that we are looking at having user email also managed by Crowd...)
I'm finding Crowd both very interesting and useful at the same time I'm having to come to terms with what we really want in a system for managing users... thanks for any ideas!