User resource with (mostly) the default update :change_password action generated by the igniter installer,AshAuthentication.Checks.AshAuthenticationInteraction bypass is satisfied, but here I am running actions directly from my code. What would be a safe way to allow access to the password fields for only the password-changen workflow, without exposing it entirely?