Project

General

Profile

Actions

BUG #4239

open

dev #4299: [SQA] : Auth module

[SQA] Create New Password: Active sessions remain valid on other devices after password change

Added by Aman Bhuiyan 2 months ago. Updated 15 days ago.

Status:
Pending
Priority:
High
Assignee:
Target version:
Start date:
02/03/2026
Due date:
% Done:

100%

Estimated time:
Spent time:

Description

Description

Module/Section: Agency → Create New Password
Profile: Agency
Issue Category: Functional

When a user is signed in on multiple browsers or devices, changing the password on one session does not invalidate active sessions on other browsers/devices.
Existing sessions remain authenticated due to valid cookies, even after the password is updated.

Steps to Reproduce

  1. Sign in to the account on Browser A.
  2. Sign in to the same account on Browser B.
  3. On Browser A, change the account password successfully.
  4. On Browser B, refresh the page or continue using the session.
  5. Observe the session state on Browser B.

Expected Result

Upon password change, all active sessions on other devices must be invalidated.
Users should be prompted to choose whether to log out from all devices or maintain trusted sessions.

Actual Result

Active sessions on other devices remain authenticated and continue to function with the old session.

Attachments


Impact Area:

Root Cause:


Additional Info

  • Tested By: Aman
Actions #1

Updated by Al Arafat Siddique 2 months ago

  • Assignee changed from Ayat Rahman to Al Arafat Siddique
  • Parent task set to #4242
Actions #2

Updated by Al Arafat Siddique 2 months ago

  • Parent task changed from #4242 to #4244
Actions #3

Updated by Al Arafat Siddique about 2 months ago

  • Assignee changed from Al Arafat Siddique to Aman Bhuiyan
Actions #4

Updated by Ayat Rahman about 1 month ago

  • Parent task changed from #4244 to #4299
Actions #5

Updated by Ayat Rahman about 1 month ago

  • % Done changed from 0 to 100
Actions #6

Updated by Aman Bhuiyan about 1 month ago

This issue is still unresolved.

Actions #7

Updated by Aman Bhuiyan 15 days ago

  • Assignee changed from Aman Bhuiyan to Ayat Rahman
Actions

Also available in: Atom PDF