feat(api): invalidate sessions on user deactivation (MS21-AUTH-004) #582
Reference in New Issue
Block a user
Delete Branch "feat/ms21-session-invalidation"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
When admin deactivates a user via PATCH /api/admin/users/:id, all sessions for that user are now deleted. Ensures deactivated users cannot continue authenticated sessions.
846c80f430toe4a56ab850