mirror of
https://github.com/fleetdm/fleet
synced 2026-05-24 09:28:54 +00:00
- Only expire sessions at reset request time when admin forces reset - Expire sessions when reset completed Prior to this, there was a possible DoS vector in which an attacker could prevent a user from taking actions in the app by constantly requesting password resets and expiring all the user's active sessions. Fixes #612 |
||
|---|---|---|
| .. | ||
| config | ||
| contexts | ||
| datastore | ||
| errors | ||
| kolide | ||
| pubsub | ||
| service | ||
| version | ||
| websocket | ||