Delete old devices when deauthorizing user sessions

This commit is contained in:
Daniel García
2019-02-16 23:06:26 +01:00
parent 93805a5d7b
commit 6027b969f5
2 changed files with 2 additions and 0 deletions

View File

@@ -171,6 +171,7 @@ fn deauth_user(uuid: String, _token: AdminToken, conn: DbConn) -> EmptyResult {
None => err!("User doesn't exist"),
};
Device::delete_all_by_user(&user.uuid, &conn)?;
user.reset_security_stamp();
user.save(&conn)