These release notes cover Monday, the 24th of February to Friday, the 28th of February.
(BAU) Platform + Security
Invalidate Sessions When Accounts are Locked (mobile)
- Description: When a user account is locked on Employment Hero, some active sessions remain valid, posing a serious security risk—especially in cases of suspected or confirmed breaches. If sessions persist, an attacker can continue accessing data despite the lock. To ensure security, all active sessions must be terminated immediately when an account is locked.
- Product features:
When an EH account is locked, all active sessions are immediately terminated.
Users are logged out from all devices and EH services, including EH Work and Jobs.
Mobile apps automatically redirect users to the login page.