Chocolate chip does not expire other sessions when password is changed or user logs out

Created on 11 July 2015, almost 10 years ago
Updated 15 May 2025, 2 days ago

A couple reporters for the Drupal 8 bug bounty have targeted drupal.org instead and noted that the session management is somewhat broken in that changing a password for the account in one session (e.g. computer #1) does not expire other open sessions (e.g. computer #2).

This is probably due to using bakery for sessions, while core SQL session would handle this correctly.

πŸ› Bug report
Status

Closed: outdated

Version

2.0

Component

Code

Created by

πŸ‡ΊπŸ‡ΈUnited States pwolanin

Live updates comments and jobs are added and updated live.
  • Security improvements

    It makes Drupal less vulnerable to abuse or misuse. Note, this is the preferred tag, though the Security tag has a large body of issues tagged to it. Do NOT publicly disclose security vulnerabilities; contact the security team instead. Anyone (whether security team or not) can apply this tag to security improvements that do not directly present a vulnerability e.g. hardening an API to add filtering to reduce a common mistake in contributed modules.

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024