metabase / metabase/metabase

Disable session reuse

Open
#61,878 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

.Project candidate Abuse/Account sharing Type:New Feature
Dominant language
Clojure
Stars
49.3k
Forks
6.8k
Avg merge
1d 13h
Merged PRs (30d)
653

Description

**Is your feature request related to a problem? Please describe.**
A customer sells Metabase access to their customers, and they're seeing that seats are being shared. We should have a flag to disallow session reuse (or just disable this altogether)

**Describe the solution you'd like**
Disable session reuse in prod environments (not in dev tokens)

**Describe alternatives you've considered**
NA

**How important is this feature to you?**
Requested by a user

**Additional context**
NA

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files or tests are named. Start by locating the session-reuse handling and the distinction between production environments and dev tokens; determine whether the requested behavior should be a configurable flag or a universal production rule. Done means session reuse is prevented in production while dev tokens retain their current behavior, with coverage for both paths.

Written by the indexing model from the issue text.

Assessment

Tech stack
clojure
Domain
authentication, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.