If config.enableUserRolesBasedOnToken is true, only let moderators and non-guests modify the password. Otherwise, only let moderators edit the password.