check old_password if passed to self-service API, require with config setting, RT...