rcpch / rcpch-audit-engine

Epilepsy12 Audit Platform
https://e12.rcpch.ac.uk/
GNU Affero General Public License v3.0
5 stars 4 forks source link

if password expired, log user out before reset #989

Closed eatyourpeas closed 1 month ago

eatyourpeas commented 1 month ago

Overview

Users whose password has expired are redirected to the password reset screen but not logged out, meaning they can still continue their session. This PR closes that loop hole by logging them out again before redirecting them