Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Invalidate token on password change #262

Open
bclaim opened this issue Nov 9, 2022 · 2 comments
Open

Invalidate token on password change #262

bclaim opened this issue Nov 9, 2022 · 2 comments

Comments

@bclaim
Copy link

bclaim commented Nov 9, 2022

Hello,

Currently, when a user changes their password, the token is not invalidated. This could be a security issue, especially during these times. I noticed there is a similar thread mentioning this which has gone off-topic, so I am creating a new issue which will hopefully stay on-topic. Is there a chance this could be implemented with priority?

Thank you.

@pesseba
Copy link

pesseba commented Nov 9, 2022

This feature is present in this another plugin: https://wordpress.org/plugins/jwt-auth/

@bclaim
Copy link
Author

bclaim commented Nov 9, 2022

We would appreciate if @Tmeister could provide their input as this issue concerns this plugin and to also keep this post on-topic.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants