Skip to content

Sessions should be invalidated if password was changed #1238

@Fasse

Description

@Fasse

If a user will change his password (e.g. in the profile or with the password forgotten function) we should invalidate all sessions and auto login of the user.

This is necessary so the user can be sure that the new password will used everywhere and a compromitted password could not be used in a saved session.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions