feat(auth): invalidate other sessions for user if the email or password are changed (#684)

* feat(auth): invalidate other sessions for user if the email or password are changed

* fix(auth): handling credentials change in a legacy protocol scenario

* fix(auth): leave only the newly created session when changing credentials
This commit is contained in:
Karol Sójko
2023-08-07 10:02:47 +02:00
committed by GitHub
parent 8e47491e3c
commit f39d3aca5b
35 changed files with 488 additions and 335 deletions
@@ -124,7 +124,7 @@ export class SignInWithRecoveryCodes implements UseCaseInterface<AuthResponse202
await this.clearLoginAttempts.execute({ email: username.value })
return Result.ok(authResponse as AuthResponse20200115)
return Result.ok(authResponse.response as AuthResponse20200115)
}
private async validateCodeVerifier(codeVerifier: string): Promise<boolean> {