That does exactly what you want. If the session is not privileged anymore because it was authenticated too long ago, the user needs to provide their old password again.
steep-lamp-91158
10/08/2024, 12:15 PM
You can reduce the time a session is considered privileged as needed.
f
fast-eve-41839
10/08/2024, 12:16 PM
Aaah ok, so I could basically set that to 1min or something and it would always be required if you want to change password. Thanks!
s
steep-lamp-91158
10/08/2024, 12:23 PM
I think you can even set 0s and it will be strictly required every time, but from a UX perspective it really makes more sense to not ask about the password if you literally just provided it.