calm-needle-46078
07/21/2022, 2:33 PMfast-lunch-54279
fast-lunch-54279
calm-needle-46078
07/21/2022, 4:13 PMcalm-needle-46078
07/21/2022, 4:15 PMmagnificent-energy-493
fast-lunch-54279
calm-needle-46078
07/21/2022, 6:13 PMmagnificent-energy-493
we want invalidate whole user session (+ all tokens from all clients)You can revoke all tokens with this endpoint https://www.ory.sh/docs/hydra/reference/api#operation/revokeConsentSessions and invalidate the authentication session (at ory hydra! the user session has to be handled in your identity provider) here https://www.ory.sh/docs/hydra/reference/api#operation/revokeAuthenticationSession the identity management (+ user sessions) would be handled in your identity provider, let me know if something is still unclear 🙂
calm-needle-46078
07/22/2022, 10:30 AMmagnificent-energy-493
the attacker can continue to use applicationif you are looking for individual user sessions you have to handle that in your application/identity management solution (for example Ory Kratos)
calm-needle-46078
07/22/2022, 11:08 AMcalm-needle-46078
07/22/2022, 2:29 PMcalm-needle-46078
07/25/2022, 7:53 AMfast-lunch-54279
calm-needle-46078
07/26/2022, 7:36 AM