Comment 2 for bug 996595

Revision history for this message
Derek Higgins (derekh) wrote : Re: Following a password compromise and subsequent password change, tokens remain valid.

yes that would solve my initial observation

in addition to this I think tokens should also be invalidated when a account is disabled currently they don't seem to be.