Closed (fixed)
Project:
Drupal core
Version:
5.x-dev
Component:
user system
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
23 Apr 2007 at 14:17 UTC
Updated:
8 May 2007 at 08:16 UTC
Most users usually (only?) change their password when they suspect it has been compromised. Therefore, when a password is changed, it is sensible to destroy all existing open sessions for that user account except the one that changed the password.
Patch attached.
| Comment | File | Size | Author |
|---|---|---|---|
| user-pass-patch.txt | 820 bytes | bjaspan |
Comments
Comment #1
moshe weitzman commentedthats perfectly sensible. rtbc.
Comment #2
kbahey commented+1, as I said on the devel mailing list.
Comment #3
dries commentedGood catch. Committed to CVS HEAD. Thanks!
Comment #4
m3avrck commentedThis should be in 5 too, no?
Comment #5
bjaspan commentedI'd say so. I do not think it is worthy of a security advisory but it is a security improvement.
Comment #6
drummCommitted to 5.
Comment #7
(not verified) commented