Actions
Story #41
openEpic #40: Failure to Invalidate Session After Password Change
Invalidate All Active Sessions After Password Change
Start date:
01/05/2026
Due date:
% Done:
0%
Estimated time:
Acceptance Criteria:
All active sessions for the user are invalidated immediately
Server-side session data is destroyed
JWT / session tokens issued before password change become unusable
Re-authentication required for all devices
No active session remains after password update
DOR:
No
Story Points:
Work Type:
Feature
User Impact:
Technical Area:
Release Narrative:
Planned Sprint:
Completed In Sprint:
Spillover Reason:
Deployment Reference URL:
Description
As a system, I want to destroy all active sessions associated with a user account when the password is changed so that old credentials cannot be used to access the system.
Actions