Closed Bug 1578805 Opened 6 years ago Closed 6 years ago

When changing password or enabling 2fa, previous sessions should be revoked in Bugzila

Categories

(bugzilla.mozilla.org :: General, enhancement)

Production
enhancement
Not set
normal

Tracking

()

RESOLVED FIXED

People

(Reporter: dkl, Assigned: dkl)

Details

Attachments

(1 file)

Currently current login sessions are left alone and so any other browsers that are logged in for an account remain logged in. For better security, we should revoke all other login sessions when a password is changed, or 2fa is enabled/disabled.

Attached patch 1578805_1.patchSplinter Review
Attachment #9090537 - Flags: review?(kohei.yoshino)
Attachment #9090537 - Flags: review?(imadueme)
Attachment #9090537 - Flags: review?(imadueme) → review+
Attachment #9090537 - Flags: review?(kohei.yoshino)

Will merge right before deployment.

Flags: needinfo?(dkl)

Merged to master.

Group: bugzilla-security
Status: ASSIGNED → RESOLVED
Closed: 6 years ago
Flags: needinfo?(dkl)
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: