Permission change session invalidation
This commit is contained in:
parent
0fbbfdc997
commit
4da6e6fb5f
@ -619,7 +619,19 @@ class User implements JsonSerializable
|
||||
$failed = [];
|
||||
$reasons = [];
|
||||
if (isset($isAdmin)) {
|
||||
$stmt = $db->prepare("UPDATE egb_benutzer SET isadmin = :ADM WHERE id = :ID");
|
||||
// Clear tokens to revoke access if logged in
|
||||
$stmt = $db->prepare(
|
||||
"UPDATE
|
||||
egb_benutzer
|
||||
SET
|
||||
isadmin = :ADM,
|
||||
token = NULL,
|
||||
tokenExpiry = NULL,
|
||||
refreshToken = NULL,
|
||||
refreshExpiry = NULL
|
||||
WHERE
|
||||
id = :ID"
|
||||
);
|
||||
$stmt->bindValue(":ADM", $isAdmin);
|
||||
$stmt->bindValue(":ID", $this->id);
|
||||
try {
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user