News:

AbanteCart v1.4.3 is released.

Main Menu
support

Force users to log out

Started by fiif, December 22, 2016, 07:43:18 AM

Previous topic - Next topic

fiif

Hey guys, I have an issue in which the password on my admin section was update as it was potentially comprised. However I was also logged in to that account on a different computer and noticed I could still make changes from that one even after the password had been updated. Is there a way to close all connections to a user and force them to sign back in? I tried even disabling the account however any computer logged in could still make changes effecting the install. Cheers for any advise.

eCommerce Core

Hello fiif and welcome to AbanteCart forum

Currently, if you have active login in any computer it will stay active until session expires or you logout. 
One thing that you can do is set shorter session expiration time in settings.

Ideally, I think, we need to add automatic logout of user if password was changed. This will require some code update.
Let us discuss this.

fiif

Thanks for the reply. Perfectly I'll set that to a minute over the weekend , should do the job.

Cheers for the quick reply

Forum Rules Code of conduct
AbanteCart.com 2010 -