Impact
When a user changes their password, browser sessions are correctly invalidated via cycle_session_keys(), but DRF API tokens (wlu_* prefix) stored in authtoken_token are not revoked.
Patches
References
Thanks to Sang Yu Jeon for reporting this via GitHub.
Impact
When a user changes their password, browser sessions are correctly invalidated via
cycle_session_keys(), but DRF API tokens (wlu_*prefix) stored inauthtoken_tokenare not revoked.Patches
References
Thanks to Sang Yu Jeon for reporting this via GitHub.