AppFlowy-IO / AppFlowy-IO/AppFlowy

[FR] Question / Feature Request: SECURITY - Sessions remain active across devices after password change

Abierto
#8,839 1 comentario 1 reacción 1 asignado Reclamado por @LucasXu0 Ver en GitHub
Q3 26
Lenguaje dominante
Dart
Estrellas
76.6k
Forks
6k
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

### Description

Hello AppFlowy Team and Community,

I noticed that when a user changes their account password, other currently logged-in devices (such as web, desktop PCs or the mobile app) remain authenticated and can continue to access the data without being forced to log out or re-authenticate.

Thank you for this amazing project!

### Impact

This is a significant security flaw. If a user's account is compromised or a device is lost/stolen, changing the password does not protect the account, as the unauthorized person or device will maintain full access indefinitely.

### Additional Context

_No response_

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.