Problem Statement
After a password reset, what session hygiene steps should the app enforce?
Explanation
Revoke all old sessions and tokens. Rotate refresh tokens. Invalidate magic links. Ask the user to sign in again on all devices. Notify the user by email or push so they can spot abuse. Log the event with a trace id so support can help quickly.
Code Solution
SolutionRead Only
onPasswordChange: revokeAllSessions(userId); rotateTokens(userId); sendSecurityNotice(userId)
