Why?
Im all for terminating sessions if the user wants it, but there are valid reasons to change passwords without knowledge of a breach.
Fwiw, terminating old sessions can be pretty hard in SSO systems and similar, though.
Im all for terminating sessions if the user wants it, but there are valid reasons to change passwords without knowledge of a breach.
Fwiw, terminating old sessions can be pretty hard in SSO systems and similar, though.
I always wondered how they addressed the state problem of cookie bearer tokens.