Skip to content
Snippets Groups Projects
  1. Jan 23, 2020
    • Eugen Rochko's avatar
      Fix password change/reset not immediately invalidating other sessions · 9c72d360
      Eugen Rochko authored
      While making browser requests in the other sessions after a password
      change or reset does not allow you to be logged in and correctly
      invalidates the session making the request, sessions have API tokens
      associated with them, which can still be used until that session
      is invalidated.
      
      This is a security issue for accounts that were already compromised
      some other way because it makes it harder to throw out the hijacker.
      9c72d360
  2. Jan 22, 2020
  3. Jan 21, 2020
  4. Jan 20, 2020
  5. Jan 18, 2020
  6. Jan 17, 2020
  7. Jan 15, 2020
  8. Jan 14, 2020
Loading