Skip to content

Existing auth tokens are not revoked when a user's password is changed or reset #8651

Description

@bakirFS

How are you running Flagsmith

  • Self Hosted with Docker
  • Self Hosted with Kubernetes
  • SaaS at flagsmith.com
  • Some other way (add details in description below)

Describe the bug

Changing or resetting a password does not revoke credentials that were already issued to the user, so sessions on other browsers and devices stay logged in.

Result: a user who suspects their account is compromised cannot lock an attacker out by changing their password.

Steps To Reproduce

  1. Log in to the dashboard as the same user in Browser A and Browser B
  2. In Browser A change the password.
  3. In Browser B, refresh the page
  4. Browser B is still logged in.

Expected behavior

After a password change or reset, the token issued to the user is revoked, and other sessions have to log in again.

Screenshots

No response

Activity

  1. added theissue type on Oct 1, 2026
  2. changed the issue type fromtoon Oct 1, 2026
  3. self-assigned this
    on Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions