Comment 19 for bug 1434034

Revision history for this message
Morgan Fainberg (mdrnstm) wrote : Re: Even if the user is disabled, can use the last token is validated

@Guang,

This is when the state of the user changes outside of the API, think read-only LDAP (AD).

@Adam,

Yep, I'll include groups. Federation has another mechanism to communicate when things are disabled/deleted. There is an open spec/bp/bug for it and explicitly avoided in this case.

@Yukihiro Kawada,

I will add you as co-author in the next proposed fix.