Invalidate old sessions/use new sessions after privilege changes #322
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Invalidate old anonymous sessionCreate new session(sign up does not sign in)All these actions have to invalidate the previous session Id
See https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html#renew-the-session-id-after-any-privilege-level-change
Duplicate of #328
Invalidate sessions after eventsto Invalidate old sessions/use new sessions after privilege changes