Skip to content

Invalidating sessions after losing permissions? #36

@mudge

Description

@mudge

While https://thecopenhagenbook.com/sessions#session-invalidation states:

All sessions of the user should also be invalidated when they gain new permissions (email verification, new role, etc) or change passwords.

Should the same be said when a user loses permissions, e.g. disabling 2FA (including indirectly by using a recovery code), or changing role from an administrator to a lower privilege?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions