Chocolate chip does not expire other sessions when password is changed or user logs out

Created on 11 July 2015, almost 10 years ago
Updated 15 May 2025, 23 days ago

A couple reporters for the Drupal 8 bug bounty have targeted drupal.org instead and noted that the session management is somewhat broken in that changing a password for the account in one session (e.g. computer #1) does not expire other open sessions (e.g. computer #2).

This is probably due to using bakery for sessions, while core SQL session would handle this correctly.

πŸ› Bug report
Status

Closed: outdated

Version

2.0

Component

Code

Created by

πŸ‡ΊπŸ‡ΈUnited States pwolanin

Live updates comments and jobs are added and updated live.
  • Security improvements

    It makes Drupal less vulnerable to abuse or misuse. Note, this is the preferred tag, though the Security tag has a large body of issues tagged to it. Do NOT publicly disclose security vulnerabilities; contact the security team instead. Anyone (whether security team or not) can apply this tag to security improvements that do not directly present a vulnerability e.g. hardening an API to add filtering to reduce a common mistake in contributed modules.

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024