Administrative DE-AUTH #173

Closed
opened 2026-01-29 00:08:22 -06:00 by EagleTrooper · 2 comments
Owner

Since the website has cookies and session length, we need a way to go in the and Instant DE-AUTH a member
Situations where we need to deauthorize the user from their 30 days token is

  1. Removal From the community
  2. Compromised Account
  3. Assisting in trouble logging in.

This can be a feature of the Membership Page recently created but DEAUTH only available to the highest level of members.

Since the website has cookies and session length, we need a way to go in the and Instant DE-AUTH a member Situations where we need to deauthorize the user from their 30 days token is 1) Removal From the community 2) Compromised Account 3) Assisting in trouble logging in. This can be a feature of the Membership Page recently created but DEAUTH only available to the highest level of members.
EagleTrooper added the Kind/Feature
Priority
Critical
Top Hitlist
labels 2026-01-29 00:08:22 -06:00
Author
Owner
Reading into potential ideas - https://cheatsheetseries.owasp.org/cheatsheets/Cookie_Theft_Mitigation_Cheat_Sheet.html
Member

This issue is mostly moot. The needs to temporarily disable an account or revoke their access have been satisfied by the state system as well as in #188 with the new support for suspending accounts.

This issue is mostly moot. The needs to temporarily disable an account or revoke their access have been satisfied by the state system as well as in #188 with the new support for suspending accounts.
Sign in to join this conversation.
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: 17th-Ranger-Battalion-ORG/milsim-site-v4#173