Account page: change your password, or sign out everywhere else
Family idea #5105, practice 4. Either action signs the account out of every other browser and unlinks every device. The browser that made the change stays signed in. - POST /api/auth/password needs the current password. A wrong one returns 403, not 401, so this browser doesn't read as signed out, and it counts against the sign-in throttle. A short new password returns 400. - POST /api/auth/sign-out-elsewhere does the same sign-out without a password change. Called from a device, it keeps that device linked. - _sign_out_elsewhere moves session_epoch on and deletes device tokens. The reset route now uses it too, keeping no device. - The page is renamed from "Linked devices" to "Account", in the router title and both nav entries. Its sections are Linked devices, Password (one short line, then the form) and Sessions (a single "Sign out everywhere else" row in the device rows' style), per preference 188: one line each, no paragraphs. - docs/public-hosting.md says how sessions end, and why a browser session isn't listed the way a device is: it is a signed cookie, ended by moving the epoch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -48,7 +48,8 @@ const router = createRouter({
|
||||
meta: { title: "Sync", requiresAuth: true, requiresDesktop: true },
|
||||
},
|
||||
{
|
||||
// Per-user account: linked devices (native-client sync tokens). Any user.
|
||||
// Per-user account: linked devices (native-client sync tokens), the password,
|
||||
// and signing out everywhere else. Any user.
|
||||
//
|
||||
// The mirror of `requiresDesktop` above: this one needs a SERVER. The desktop
|
||||
// is itself one of the devices this page lists, so offline the list is always
|
||||
@@ -58,7 +59,7 @@ const router = createRouter({
|
||||
path: "/account",
|
||||
name: "account",
|
||||
component: () => import("../views/AccountView.vue"),
|
||||
meta: { title: "Linked devices", requiresAuth: true, requiresServer: true },
|
||||
meta: { title: "Account", requiresAuth: true, requiresServer: true },
|
||||
},
|
||||
{
|
||||
path: "/login",
|
||||
|
||||
Reference in New Issue
Block a user