Comment 3 for bug 996595

Revision history for this message
Joseph Heck (heckj) wrote : Re: Following a password compromise and subsequent password change, tokens remain valid.

Russell, I agree with your status on the bug - and it's a good one to get into place both for the password change option and the account disabled mechanism.

Derek - do you have any interest in submitting a patch for this, or are you more focused on making us aware? (i.e. would you like the bug assigned to you?)