-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Labels
priority: lowtype: enhancementnew feature or requestnew feature or requesttype: new featureA new featureA new featuretype: securityIssue related to SecurityIssue related to Security
Description
Is your feature request related to a problem? Please describe.
It should be possible for an admin to deauthenticate an individual user or a set of users.
Describe the solution you'd like
Provide an option visible to admins on a user's page that invalidates any sessions.
Provide an option to invalidate all user sessions via the admin page.
Additional context
This could be achieved on a user level by keeping the user's id in redis with the time of invalidation.
Incoming JWTs to services will require a quick check of the token's user id, and a comparison of the creation time and time of invalidation
Metadata
Metadata
Assignees
Labels
priority: lowtype: enhancementnew feature or requestnew feature or requesttype: new featureA new featureA new featuretype: securityIssue related to SecurityIssue related to Security