Skip to content

Invalidate sessions and bearer tokens on password change/reset - #695

Merged
MarcelGeo merged 1 commit into
developfrom
invalidate_tokens_on_reset
Oct 7, 2026
Merged

MarcelGeo merged 1 commit into
developfrom
invalidate_tokens_on_reset

Conversation

@varmar05

@varmar05 varmar05 commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

On password change/reset bump auth version which is bound to tokens - which would immediately invalidate all previously issued tokens. Legacy cookies and tokens map to version 0, so deploying does not log out existing users.

There is a new config variable to make PERMANENT_SESSION_LIFETIME for web clients configurable.

Legacy cookies and tokens map to version 0, so deploying does not log
out existing users. Make PERMANENT_SESSION_LIFETIME configurable.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@varmar05
varmar05 requested a review from MarcelGeo October 7, 2026 08:11
@coveralls

Copy link
Copy Markdown

Coverage Report for CI Build 37591655582

Coverage increased (+0.08%) to 92.84%

Details

  • Coverage increased (+0.08%) from the base build.
  • Patch coverage: 88 of 88 lines across 6 files are fully covered (100%).
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 11410
Covered Lines: 10593
Line Coverage: 92.84%
Coverage Strength: 0.93 hits per line

💛 - Coveralls

@MarcelGeo MarcelGeo left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok.

@MarcelGeo
MarcelGeo merged commit 038d0a2 into develop Oct 7, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants