Quantcast
Channel: Mendix Forum Questions
Viewing all articles
Browse latest Browse all 83469

No session expiration after password change

$
0
0
We have observed that after changing our password, the session identifier stays the same. In doing so, when an adversary has access to the current session identifier, he will manage to maintain an active session. How can I enforce this?

Viewing all articles
Browse latest Browse all 83469

Trending Articles