Invalidate Session on 2FA Activation/Change

S

Steffen

Guest
Member
It seems like it's best-practise to invalidate other sessions on 2FA activation/change ([1], [2]). At the moment, XenForo seems to invalidate other sessions on password change but not on 2FA activation/change.

The scenario goes like this:
  1. Log in to the same account with two different browsers
  2. Enable 2FA in one of the logged-in sessions
  3. Observe that the other browser's session remains active
This has been reported to us via email (with the unfortunately common...

Read more

Continue reading...
 
BlackSpigot General Chat
Rules Help Users
    Stacksyz @ Stacksyz: Hi how is everyone??? Hello, Im good how are you?
    Top