mirror of
https://github.com/keycloak/keycloak.git
synced 2025-12-30 11:29:57 -06:00
Invalidate sessions created with remember me when remember me is disabled for realm
Closes #43328 Signed-off-by: Giuseppe Graziano <g.graziano94@gmail.com>
This commit is contained in:
committed by
GitHub
parent
38909da47d
commit
bda0e2a67c
@@ -16,3 +16,5 @@ When you save this setting, a `remember me` checkbox displays on the realm's log
|
||||
.Remember Me
|
||||
image:images/remember-me.png[Remember Me]
|
||||
|
||||
WARNING: Note that disabling the "Remember me" option will invalidate all sessions created with the "Remember me" checkbox selected during login, requiring users to log in again. Any refresh tokens related to these sessions will also become invalid.
|
||||
Note also that the sessions will not be invalidated immediately when the switch is disabled, but only when a cookie or token associated with an invalid session is used. This means that disabling and then re-enabling the "Remember me" switch cannot be used to invalidate old sessions.
|
||||
|
||||
@@ -12,6 +12,12 @@ The `log-console-color` previously defaulted to `false`, but it will now instead
|
||||
|
||||
You may still explicitly disable color support by setting the option to `false`.
|
||||
|
||||
=== User sessions created with "Remember Me" are no longer valid if "Remember Me" is disabled for the realm
|
||||
|
||||
When the "Remember Me" option is disabled in the realm settings, all user sessions previously created with the "Remember Me" flag are now considered invalid.
|
||||
Users will be required to log in again, and any associated refresh tokens will no longer be usable.
|
||||
User sessions created without selecting "Remember Me" are not affected.
|
||||
|
||||
// ------------------------ Deprecated features ------------------------ //
|
||||
== Deprecated features
|
||||
|
||||
|
||||
Reference in New Issue
Block a user