Project

General

Profile

Actions

Patch #44578

open

Invalidate sessions and autologin tokens when an email address is changed or deleted

Added by Jens Krämer about 11 hours ago. Updated about 10 hours ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Accounts / authentication

Description

So far, changing or deleting an email address of a user deleted only their
password recovery tokens.
With this change, as defense in depth against hijacked
sessions, it now deletes their auto login and session tokens as well, like a
password change does, so that all sessions of the user end.


Files

Actions #1

Updated by Go MAEDA about 10 hours ago

  • Category set to Accounts / authentication
  • Target version set to Candidate for next minor release
Actions

Also available in: Atom PDF