

























As an initial action, we’re introducing the ability to set passwords as compromised, with the option to immediately sign out all active sessions for the affected user. This triggers a reset password session task, requiring the user to set a new password on their next sign-in. Additional actions will be introduced in the future.
If you need to protect all users at once—such as during a suspected platform-wide security incident—you can require a password reset for every account in your instance.
This is currently done by setting all existing passwords as compromised, which will trigger a reset password session task for affected users. Each user will be required to set a new password the next time they sign-in.
When only a single account is at risk, you can require a password reset for that user alone.
This action triggers a reset password session task for the user, ensuring they must change their password before continuing.
All new instances have password reset session task enabled by default. Existing instances must manually opt-in via the Reset password session task update on the Updates page.
If you’re using custom authentication flows, make sure your application handles:
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。