Skip to content

6.0.2

Latest

Choose a tag to compare

@AltamashShaikh AltamashShaikh released this 07 Sep 02:52
· 5 commits to 6.x-dev since this release
1d3386a
  • Deleting a user now removes the OAuth 2.0 clients they own, together with the access tokens, refresh tokens and authorization codes issued for those clients. The credentials the deleted user was granted for clients owned by somebody else are removed as well, while those clients themselves are kept.
  • Clients whose owner no longer exists are no longer accepted in any grant and their tokens no longer authenticate, so credentials left behind by an incomplete cleanup cannot start acting as a different user that is later given the same login.
  • Clients removed because their owner was deleted are now reported in the activity log, and the new OAuth2.deleteClientWithOwner.end event reports them to other plugins.
  • The access token and authorization code tables are now indexed by user_login, so deleting a user no longer scans them in full.
  • A plugin listening to OAuth2.deleteClientWithOwner.end that throws no longer stops the remaining removed clients from being reported. The clients themselves were already deleted before the event was posted, so only their activity log entries were affected.