spiderplant@infosec.pubtolemmy.ml meta@lemmy.ml•I'm going to assume the admins here all have 2FA on their accounts, right?
3·
1 year agoReally curious to see how they kill the existing tokens, and whether admins have tools to easily clear all sessions. On one of the Matrix chats someone suggested that the tokens have a one year expiry date!
Looks like you’re right, admins will just need to update the JWT secret.