#Session Persistence After Password Change

1 messages · Page 1 of 1 (latest)

primal dove
#

Description: We've identified an issue where, after a password change, all active sessions remain logged in. Ideally, for security reasons, all sessions should be automatically logged out whenever a password is changed.

Steps to Reproduce:

  1. Log in to your OpenAI account on multiple devices/browsers.
  2. Change your password on one of the devices.
  3. Check your account status on the other device(s).

Expected Result: All sessions should be logged out and require the new password to log back in.

Actual Result: The sessions remain active even after the password change.

Frequency: This issue has been reported by multiple users and appears to be consistent.

Additional Information: This issue poses serious security risks as unauthorized users may maintain access to the account even after a password change.
See: #1154123038053380126 #1157322575941210224 #1158746675490324511 #1156924651654619206

primal dove
iron leaf
primal dove
primal dove
#

Or just you logged in in someone's computrer and forgotten to logout