Comment 4 for bug 1050025

Revision history for this message
Joseph Heck (heckj) wrote : Re: Potential problem with fix for "Revoking a role does not affect existing tokens (CVE-2012-4413)"

This patch isn't invalidating all tokens - just the tokens for the relevant user.

Russel and/or Thierry - can you explain why this is a bug? I don't believe this bug is valid. not confirmed.