MSA-12-0008: Unsynchronised access via tokens

MSA-12-0008: Unsynchronised access via tokens

by Michael de Raadt -
Number of replies: 0
Topic: WS tokens & user->deleted status are out of sync
Severity: Minor
Versions affected: 2.2, 2.1 to 2.1.3+, 2.0 to 2.0.6+ (1.9 not affected)
Reported by: Eloy Lafuente
Issue no.: MDL-28126
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28126

Description:

A user deleted on the server was able to access a site while they continued to use a token.