Invalidate Session on 2FA Activation/Change

It seems like it's best-practise to invalidate other sessions on 2FA activation/change ([1], [2]). At the moment, XenForo seems to invalidate other sessions on password change but not on 2FA activation/change.

The scenario goes like this:
  1. Log in to the same account with two different browsers
  2. Enable 2FA in one of the logged-in sessions
  3. Observe that the other browser's session remains active
This has been reported to us via email (with the unfortunately common...

Read more

Читать далее...
 
Активность
Пока что здесь никого нет
Назад
Верх Низ