プロジェクト

全般

プロフィール

Vote #75544

完了

Expire all other sessions on password change

Admin Redmine さんが3年以上前に追加. 3年以上前に更新.

ステータス:
Closed
優先度:
通常
担当者:
-
カテゴリ:
Security_51
対象バージョン:
開始日:
2022/05/09
期日:
進捗率:

90%

予定工数:
category_id:
51
version_id:
81
issue_org_id:
17796
author_id:
347
assigned_to_id:
1188
comments:
4
status_id:
5
tracker_id:
3
plus1:
0
affected_version:
closed_on:
affected_version_id:
ステータス-->[Closed]

説明

To improve user account security, we believe it is a good practice to expire all other active user sessions (on other computers or browsers) once a user changes their password.

Please find attached a patch that implements this feature against current trunk; tests included.


journals

Good practice I think. Same as #17717, I'd like to have some guidance about how we deal with that kind of patch. I didn't test this one but I'll review it and test it when I know what to do.
--------------------------------------------------------------------------------
We can commit this patch now, but I'd like to change the new column to @passwd_changed_on@ instead of @password_changed_at@.
--------------------------------------------------------------------------------

--------------------------------------------------------------------------------
Added in r13412 with the column name requested by Jean-Philippe, and a minor typo fixed in the test. Thanks!
--------------------------------------------------------------------------------

Admin Redmine さんが3年以上前に更新

  • カテゴリSecurity_51 にセット
  • 対象バージョン2.6.0_81 にセット

他の形式にエクスポート: Atom PDF

いいね!0
いいね!0