You mention the following:

"In particular, the password field cannot be empty (in fact, an empty password should be interpreted as the user not wanting to change password)"

So, does that mean that an empty password is still allowed when making the changes? Or what do mean by this.


Yes, empty password is allowed when making changes. What I was trying to say was that if a user left the password field empty when changing his/her account information, it should be interpreted as keeping the current password rather than setting an empty password.


Oh I see, thanks