From 6ca216ab6e86b9062616fa727ee3be169bbd0811 Mon Sep 17 00:00:00 2001 From: Julian Lam Date: Wed, 12 Jan 2022 11:09:02 -0500 Subject: [PATCH] feat: revoke user sessions on successful password reset --- src/user/reset.js | 1 + 1 file changed, 1 insertion(+) diff --git a/src/user/reset.js b/src/user/reset.js index 6d9e99dc58..b8a77a4d08 100644 --- a/src/user/reset.js +++ b/src/user/reset.js @@ -105,6 +105,7 @@ UserReset.commit = async function (code, password) { ]), user.reset.updateExpiry(uid), user.auth.resetLockout(uid), + user.auth.revokeAllSessions(uid), user.email.expireValidation(uid), ]); };