Actions
Patch #44578
openInvalidate sessions and autologin tokens when an email address is changed or deleted
Status:
New
Priority:
Normal
Assignee:
-
Category:
Accounts / authentication
Target version:
Description
So far, changing or deleting an email address of a user deleted only their
password recovery tokens.
With this change, as defense in depth against hijacked
sessions, it now deletes their auto login and session tokens as well, like a
password change does, so that all sessions of the user end.
Files
Updated by Go MAEDA about 10 hours ago
- Category set to Accounts / authentication
- Target version set to Candidate for next minor release
Actions