-
Type:
Bug
-
Resolution: Unresolved
-
Priority:
Low
-
Component/s: Account - Deletion
-
None
-
1
-
Minor
Issue Summary
Deleted accounts are not immediately logged out of all clients (e.g. Trello mobile), allowing continued usage and leading to an inconsistent account state when recreating accounts.
Steps to Reproduce
- Sign up for Trello using an email address on the web.
- Log in using this account to the Mobile Trello app.
- On web:
- Navigate to account preferences.
- Select "Delete your account".
- Complete the deletion flow and confirm the account deletion.
- After successful deletion on the web, switch back to the Trello mobile app (where the same account was previously logged in).
- Attempt to create a new board.
Expected Results
- When an account is deleted, all active sessions across all clients (web, mobile, desktop) should be invalidated.
- The mobile Trello app should log the user out automatically.
The deleted account should not be able to create boards or perform any actions.- Deleted account cannot create boards. Those endpoints return 403 as expected.
Actual Results
- The mobile Trello client remains logged in with the deleted account.
The user can continue to perform actions (e.g., create boards) using what should be a deleted account/session.- Deleted account cannot create boards. Those endpoints return 403 as expected.
- There is no immediate logout or clear indication that the account has been deleted on the server side.
- Getting 200s back for the /me endpoint and then 403 unauthorized permission requested for things like boards. Sockets will also give unauthorized messages.
Workaround
Currently, there is no known workaround for this behaviour. A workaround will be added here when available.