AppFlowy-IO / AppFlowy-IO/AppFlowy
[FR] Question / Feature Request: SECURITY - Sessions remain active across devices after password change
- Vorherrschende Sprache
- Dart
- Sterne
- 76.6k
- Forks
- 6k
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
### Description
Hello AppFlowy Team and Community,
I noticed that when a user changes their account password, other currently logged-in devices (such as web, desktop PCs or the mobile app) remain authenticated and can continue to access the data without being forced to log out or re-authenticate.
Thank you for this amazing project!
### Impact
This is a significant security flaw. If a user's account is compromised or a device is lost/stolen, changing the password does not protect the account, as the unauthorized person or device will maintain full access indefinitely.
### Additional Context
_No response_
Beitragsleitfaden
Für dieses Repository ist kein Beitragsleitfaden indexiert
Bewertung
Dieses Issue wurde noch nicht bewertet.