3 ms·
What approaches do other OAuth providers take to this problem? Revoking all OAuth tokens on a password change/reset takes away a good chunk of the value that ma
by madmotive 17y ago
What approaches do other OAuth providers take to this problem? Revoking all OAuth tokens on a password change/reset takes away a good chunk of the value that many people get from using OAuth.
- tomjen2 17y agoAgreed, but would it be difficult to have a checkbox marked "revoke all permissions to use my account from all applications" to the reset password menu?
- neilk 17y agoThat's overkill. Perhaps, one day, there will be a need to suspend all oAuth authorizations while a rogue app is identified.
- orblivion 17y agoEvery OAuth site has a "log in with Twitter" feature, correct? Maybe Twitter could organize things such that, when you change your password, you're automatically logged out of every OAuth site?