0009651: merchant backend
Summary0009651: When changing the instance password we may want to revoke old access tokens
DescriptionCurrently, unless the tokens expire or are explicitly revoked, they stay valid even if the instance password is changed.
We may want to think about revoking all old tokens issued before the change.
related to 0009556: address merchant auth token weirdness 


Christian Grothoff

2025-03-24 13:47

manager

I think this should be an option. Just because someone changes their instance password doesn't mean that they intend to revoke all access tokens. So the SPA could have a checkbox "revoke access tokens" and submit that boolean with the password change request. I guess the safe(r) default is to set it by default, but I think there are legitimate cases where you want the access tokens to remain valid, so we should give users a way to disable that.

