Invalidate Session on 2FA Activation/Change (1 Viewer)

S

Steffen

Guest
It seems like it's best-practise to invalidate other sessions on 2FA activation/change ([1], [2]). At the moment, XenForo seems to invalidate other sessions on password change but not on 2FA activation/change.

The scenario goes like this:
  1. Log in to the same account with two different browsers
  2. Enable 2FA in one of the logged-in sessions
  3. Observe that the other browser's session remains active
This has been reported to us via email (with the unfortunately common...

Read more

Continue reading...
 
Top