AppFlowy-IO / AppFlowy-IO/AppFlowy

[FR] Question / Feature Request: SECURITY - Sessions remain active across devices after password change

Offen
#8,839 1 Kommentar 1 Reaktion 1 zugewiesene Person Beansprucht von @LucasXu0 Auf GitHub ansehen
Q3 26
Vorherrschende Sprache
Dart
Sterne
76.6k
Forks
6k
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

### Description

Hello AppFlowy Team and Community,

I noticed that when a user changes their account password, other currently logged-in devices (such as web, desktop PCs or the mobile app) remain authenticated and can continue to access the data without being forced to log out or re-authenticate.

Thank you for this amazing project!

### Impact

This is a significant security flaw. If a user's account is compromised or a device is lost/stolen, changing the password does not protect the account, as the unauthorized person or device will maintain full access indefinitely.

### Additional Context

_No response_

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.