Commit Graph
19 Commits
Author SHA1 Message Date
Classic298 21e390561d fix: revoke existing sessions when a password changes (#28725)
Changing a password left every other logged-in device working until the JWT expired on its own, up to four weeks with the default settings. The hardening docs already promise the opposite: with Redis configured a password change is supposed to put the user's tokens on the revocation list, but only sign-out and OIDC back-channel logout ever wrote to it.

Both password-change paths, self-service and an admin resetting someone's password, now stamp the per-user revocation marker that token validation already checks, so every session issued before the change stops working. The acting device is signed out as well and asked to sign in again, which is the safer default when the password is being changed precisely because the old one may be compromised. Without Redis nothing can be revoked, as before, and the backend now logs a warning saying so.

The marker is written through one shared helper, so its lifetime follows the configured JWT lifetime instead of a fixed 30 days and never expires at all when JWT_EXPIRES_IN disables expiry. Back-channel logout picks that up too, where a long or disabled JWT lifetime previously let the marker expire while the tokens it revoked were still valid. API keys keep working, they are separate credentials with their own lifecycle.

Discussed in #28647.
2026-08-17 13:56:29 -07:00
Timothy Jaeryang Baek bd5d7b2e87 refac 2026-07-24 01:47:11 -04:00
Timothy Jaeryang Baek 212eec408c refac 2026-07-24 01:44:30 -04:00
Timothy Jaeryang Baek c3878b418a refac 2026-07-15 18:21:24 -04:00
Timothy Jaeryang Baek ba067258de refac 2026-07-15 17:50:26 -04:00
Timothy Jaeryang Baek 63ada24706 refac 2026-07-15 00:14:01 -04:00
Timothy Jaeryang Baek aedb6bef4e refac 2026-07-14 04:15:20 -04:00
Timothy Jaeryang Baek 1a15a62b73 chore: format 2025-08-21 04:47:28 +04:00
silentoplayz 82ed9b0a97 i18n.t: updates 2025-08-13 20:15:16 -04:00
silentoplayz 56eeed6277 feat: Add password visibility toggle to password fields w SensitiveInput.svelte component 2025-08-03 16:07:12 -04:00
Timothy Jaeryang Baek e3fa48b6ce chore: tailwind v4 migration 2025-02-15 19:27:25 -08:00
Timothy Jaeryang Baek a863f98c53 refac: toast error 2025-01-20 22:41:32 -08:00
Timothy Jaeryang Baek 4820ecc371 enh: webhook notification 2024-12-20 22:54:43 -08:00
Jannik Streidl ccc1c81256 added missing translation keys 2024-03-14 14:38:05 +01:00
Ased Mammad 3c471ee2ca feat: Migrate hardcoded strings to i18n calls 2024-03-03 00:56:24 +03:30
Jannik Streidl 705f5aecd7 svelte-sonner migration 2024-03-01 10:18:07 +01:00
Timothy J. Baek 275523e32e feat: jwt utils 2024-02-19 20:44:00 -08:00
Timothy J. Baek 77e27ce248 fix: styling 2024-01-26 21:39:53 -08:00
Timothy J. Baek 3ce8f3e8fb feat: profile update frontend integration 2024-01-26 21:22:25 -08:00