The Issue: A third party inadvertently gained access to my account (likely via a shared link containing a token). Even though I have deleted the specific photos they were looking at, they still retain full access to my account.
It seems that session tokens/cookies never expire and do not rotate. Deleting content does not invalidate their active session.
The Request: Currently, there is no way for a user to secure their account once a link is leaked.
Immediate Fix: Please implement a "Log out all devices" button in the settings so I can revoke access to unauthorized users.
System Fix: Please implement Session Token Rotation. Using a link once should not grant permanent, irrevocable access. Keys should change or expire to prevent "zombie sessions."
This is a major privacy concern for me. Please let me know how I can secure my account immediately.
Please authenticate to join the conversation.
Completed
📸 Photo AI
14 days ago
Get notified by email when there are changes.
Completed
📸 Photo AI
14 days ago
Get notified by email when there are changes.