•  
      request #15065 Changing password should revoke all OAuth2 tokens
    Infos
    #15065
    Thomas Gerbet (tgerbet)
    2020-07-07 10:30
    2020-07-03 14:01
    16329
    Details
    Changing password should revoke all OAuth2 tokens
    If a user's account is compromised by an attacker, the attacker could try to persist some of its accesses by registering an evil OAuth2 app into the account. By revoking all the ongoing OAuth2 tokens we make sure the user has purposely wanted to share its access with the app at least once.
    OAuth2 / OpenID Connect server
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2020-07-07
    Attachments
    Empty
    References

    Follow-ups