W3C

Edit comment LC-2277 for Mobile Web Best Practices Working Group

Quick access to

Previous: LC-2296 Next: LC-2297

Comment LC-2277
:
Commenter: Marc Wilson <marcwilson@google.com>

or
Resolution status:

3.3.4
Consider adding something along the lines of
"If devices persist authentication tokens then the server MUST
invalidate them if the user changes or resets their password"
This is especially important with mobile devices that are often
lost/stolen and provides a user with a way to after the fact lock the
phone out of web applications it had previously been authorised for.
(space separated ids)
(Please make sure the resolution is adapted for public consumption)


Developed and maintained by Dominique Hazaël-Massieux (dom@w3.org).
$Id: 2277.html,v 1.1 2017/08/11 06:43:56 dom Exp $
Please send bug reports and request for enhancements to w3t-sys.org