Changing Password Does Not Invalidate Logins
Cake․
I changed the password of my VRChat account and was able to log in without having to enter my new credentials.
I expected the login token to be invalidated when I change my password and every active session to end, returning the player to the login interface.
This is important to stop a malicious actor of using an account they gained access to.
I would propose the ability to invalidate logins when the 2FA is added/modified or the password has been altered. This would also include deleting locations the user granted login access to.
Log In
Tom․exe
like twitch (and many others) do, if you change your password, it invalidates all service connection / keys that you have
owlboy
Tom․exe: Any some give you a choice and make it optional. Either way, a good thing to do.