-
Type:
Suggestion
-
Resolution: Won't Do
-
None
-
Component/s: None
-
1
NOTE: This suggestion is for Confluence Server. Using Confluence Cloud? See the corresponding suggestion.
It would be quite important to make sure that active user sessions (remember me token) are removed, when a user's details in LDAP are changed.
This should be applied on the next LDAP sync, and if any of the user's attributes are updated, the user's remember me token should be removed.
A good solution could be to add "Deactivate all sessions" button in Confluence Administration.
- relates to
-
CONFCLOUD-26432 Allow administrators to deactivate remember-me tokens for specific users
- Closed
-
CONFSERVER-29687 Allow cookie-less instance for security reasons
- Closed
- mentioned in
-
Page Loading...