Originally reported by Alexander Hook:
Failure to Invalidate Session on Password Change.
I observe that when we change password from one browser in place of session Expire from other browser its just update password from other browser and the old session got updated without being logout Steps to check session management issue on password change.
- Login account from two browsers at a time [ From Chrome browser and From Mozilla Firefox].
- Change password in setting from Chrome Browser.
- Now check Mozilla FireFox. (First Refresh then Auto Updated in Place of Expiration ).
- Your Session did not Get Updated in Place of Expiration.
Recommendations:
If Session is updating from one Browser so others should expire first to renew Session after login.
Workaround until fixed: Make sure to logout in all browsers when changing the password.
This will be released in the upcoming patch release.
--
TWiki:Main/PeterThoeny
- 2020-11-16