Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: remove login session by id #3165

Closed
wants to merge 1 commit into from
Closed

feat: remove login session by id #3165

wants to merge 1 commit into from

Conversation

burkov
Copy link

@burkov burkov commented Jun 23, 2022

Use case:

  1. User logs in with subject "A"
  2. User somehow manages to login with subject "B" (for example removing account A and creating account B)
  3. Now user is blocked by "Field 'subject' does not match subject from previous authentication." error on accepting login

This feature allows to remove login session on step (3) which will allow user to start auth from scratch.

Related issue(s)

A simpler version of #2876

Checklist

  • I have read the contributing guidelines.
  • I have referenced an issue containing the design document if my change introduces a new feature.
  • I am following the contributing code guidelines.
  • I have read the security policy.
  • I confirm that this pull request does not address a security vulnerability.
    If this pull request addresses a security. vulnerability,
    I confirm that I got green light (please contact security@ory.sh) from the maintainers to push the changes.
  • I have added tests that prove my fix is effective or that my feature works.
  • I have added or changed the documentation.

Further Comments

@burkov burkov requested a review from aeneasr as a code owner June 23, 2022 12:06
@CLAassistant
Copy link

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@burkov
Copy link
Author

burkov commented Jun 23, 2022

ooops, the right way to fix this is https://www.ory.sh/docs/hydra/advanced#using-login_hint-with-different-subject

@burkov burkov closed this Jun 23, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants