The current password expire logic may fail to send a user to the password expiry page directly. (Further request to allura will send them to the expiry change page, but if you have non-Allura pages on the domain, the user could redirect off to those and miss the password reset form).
Fixed on branch db/7756