You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Deleting a user now removes the OAuth 2.0 clients they own, together with the access tokens, refresh tokens and authorization codes issued for those clients. The credentials the deleted user was granted for clients owned by somebody else are removed as well, while those clients themselves are kept.
Clients whose owner no longer exists are no longer accepted in any grant and their tokens no longer authenticate, so credentials left behind by an incomplete cleanup cannot start acting as a different user that is later given the same login.
Clients removed because their owner was deleted are now reported in the activity log, and the new OAuth2.deleteClientWithOwner.end event reports them to other plugins.
The access token and authorization code tables are now indexed by user_login, so deleting a user no longer scans them in full.
A plugin listening to OAuth2.deleteClientWithOwner.end that throws no longer stops the remaining removed clients from being reported. The clients themselves were already deleted before the event was posted, so only their activity log entries were affected.