Fix 2FA/sign-in token sessions being valid after password change (#14802)
If someone tries logging in to an account and is prompted for a 2FA code or sign-in token, even if the account's password or e-mail is updated in the meantime, the session will show the prompt and allow the login process to complete with a valid 2FA code or sign-in token
parent
9870b175
Aucune branche associée trouvée
Aucune étiquette associée trouvée
Affichage de
- app/controllers/api/base_controller.rb 1 ajout, 1 suppressionapp/controllers/api/base_controller.rb
- app/controllers/auth/sessions_controller.rb 21 ajouts, 1 suppressionapp/controllers/auth/sessions_controller.rb
- app/controllers/concerns/sign_in_token_authentication_concern.rb 9 ajouts, 7 suppressions...trollers/concerns/sign_in_token_authentication_concern.rb
- app/controllers/concerns/two_factor_authentication_concern.rb 18 ajouts, 14 suppressions...controllers/concerns/two_factor_authentication_concern.rb
- app/controllers/concerns/user_tracking_concern.rb 3 ajouts, 4 suppressionsapp/controllers/concerns/user_tracking_concern.rb
- app/models/user.rb 19 ajouts, 6 suppressionsapp/models/user.rb
- spec/controllers/auth/sessions_controller_spec.rb 7 ajouts, 7 suppressionsspec/controllers/auth/sessions_controller_spec.rb
Chargement en cours
Veuillez vous inscrire ou vous se connecter pour commenter