How are you running Flagsmith
Describe the bug
Changing or resetting a password does not revoke credentials that were already issued to the user, so sessions on other browsers and devices stay logged in.
Result: a user who suspects their account is compromised cannot lock an attacker out by changing their password.
Steps To Reproduce
- Log in to the dashboard as the same user in Browser A and Browser B
- In Browser A change the password.
- In Browser B, refresh the page
- Browser B is still logged in.
Expected behavior
After a password change or reset, the token issued to the user is revoked, and other sessions have to log in again.
Screenshots
No response
How are you running Flagsmith
Describe the bug
Changing or resetting a password does not revoke credentials that were already issued to the user, so sessions on other browsers and devices stay logged in.
Result: a user who suspects their account is compromised cannot lock an attacker out by changing their password.
Steps To Reproduce
Expected behavior
After a password change or reset, the token issued to the user is revoked, and other sessions have to log in again.
Screenshots
No response