-
-
Notifications
You must be signed in to change notification settings - Fork 61
Open
Description
While https://thecopenhagenbook.com/sessions#session-invalidation states:
All sessions of the user should also be invalidated when they gain new permissions (email verification, new role, etc) or change passwords.
Should the same be said when a user loses permissions, e.g. disabling 2FA (including indirectly by using a recovery code), or changing role from an administrator to a lower privilege?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels