Skip to content

AppPasswordService: invalidate previously generated app passwords wit… - #80

Open
dusfor72 wants to merge 1 commit into
rotdrop:masterfrom
dusfor72:patch-1
Open

dusfor72 wants to merge 1 commit into
rotdrop:masterfrom
dusfor72:patch-1

Conversation

@dusfor72

@dusfor72 dusfor72 commented Oct 6, 2026

Copy link
Copy Markdown

Fixes #79

Before generating a new z-app-generated-roundcube app password,
AppPasswordService::generateAppPassword() now invalidates the user's existing
permanent tokens with the same name. The new token replaces the old one in the
CardDAV account right afterwards, so the old one is no longer needed.

Without this, every login adds another valid permanent token and the old ones
are never removed (61 accumulated in our setup).

Tested: after one logout/login with the patch applied, exactly one token remains,
the CardDAV address book in Roundcube works, and there are no new log entries.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CardDAV provisioning: app password on every login but old ones never removed

1 participant