Browse Source

Delete old devices when deauthorizing user sessions

pull/404/head
Daniel García 6 years ago
parent
commit
6027b969f5
No known key found for this signature in database GPG Key ID: FC8A7D14C3CD543A
  1. 1
      src/api/admin.rs
  2. 1
      src/api/core/accounts.rs

1
src/api/admin.rs

@ -171,6 +171,7 @@ fn deauth_user(uuid: String, _token: AdminToken, conn: DbConn) -> EmptyResult {
None => err!("User doesn't exist"),
};
Device::delete_all_by_user(&user.uuid, &conn)?;
user.reset_security_stamp();
user.save(&conn)

1
src/api/core/accounts.rs

@ -322,6 +322,7 @@ fn post_sstamp(data: JsonUpcase<PasswordData>, headers: Headers, conn: DbConn) -
err!("Invalid password")
}
Device::delete_all_by_user(&user.uuid, &conn)?;
user.reset_security_stamp();
user.save(&conn)
}

Loading…
Cancel
Save