Comment 6 for bug 1050025

Revision history for this message
Joseph Heck (heckj) wrote : Re: Potential problem with fix for "Revoking a role does not affect existing tokens (CVE-2012-4413)"

This method invoked, when updating should be limiting it's impact to the tokens associated with the user and tenant, not all tokens for the user.