Reset/invalidate all active user logins?


#1

Is there a way for an admin of the installation to invalidate all active user logins?

We use Jira oauth as the main authentication mechanism for our phab installation. A couple of days ago the “Application Link” on Jira was removed (by mistake) and recreated. My understading is that all the oauth tokens associated with the users currently logged in in Phabricator are now invalid. So everyone is logged in but they can’t use the Jira integration (mailnly to link Diffs to Jira tickets). Logging out and logging in again works fine and you get a valid token.

Is there a way for me to force all logged in users off so they can renew their sessions?


#2

See https://secure.phabricator.com/book/phabricator/article/revoking_credentials/.

phabricator/ $ ./bin/auth revoke --type session --everywhere