Comment 1 for bug 1050025

Revision history for this message
Thierry Carrez (ttx) wrote : Re: Potential problem with fix for "Revoking a role does not affect existing tokens (CVE-2012-4413)"

Yeah, I was kinda supposing it would only invalidate the tokens for the tenant the role was granted to/revoked from... but not sure anymore now.