#[SOLVED] Behavior after blocking an user

6 messages · Page 1 of 1 (latest)

molten finch
#

Hey guys,

what is the intended behavior when I block an user which has an active session right now? Is it comparable to an IP-ban?

I have a Flutter web app which loads perfectly fine on Google Chrome, Safari and so on.

Step 1: Signing user in on web app on Google Chrome
-> Everything fine
Step 2: Block Account in the appwrite backend
Step 3: Any action in the web app
-> Nothing is loading anymore properly which is good
Step 3: Opening the web app on Safari (not signed in)
-> Nothing is loading anymore properly

somber kraken
molten finch
# somber kraken Only the account itself is blocked. You might still have a session in safari...c...

You were right. It was about an old session on Safari. (I asked the person I was testing it on and he told me that he has not been using Safari for the web app before - maybe he forgot).
After deleting all sessions before going through the steps, it worked the intended way.

But still:

  • Is it a good approach to delete all sessions when blocking a user? There might be another one trying to access the web app from this computer and browser.
  • How long are sessions stored? -> Auth Security Tab ✅
somber kraken
molten finch
# somber kraken That sounds like a good feature request. Would you be able to create a GitHub is...

Just created one https://github.com/appwrite/appwrite/issues/6061 - Thank you very much for your responses so far 🙂 Should this be marked in any way since there wont be a discussion here anymore I suppose

GitHub

🔖 Feature description When deleting a user in the appwrite backend the sessions are still stored and not deleted. Therefore a different user using the same device wont be able to sign in because th...

somber kraken