Last modified: 2012-02-08 17:32:07 UTC
Currently if a copy of your user table gets leaked out you have to regenerate the entire user_token column. I'm not even sure we have a user script to do that. The User class code should be tweaked so that if a user_token is found to be NULL when a user is logging in a new one will be generated and the row will be updated. This way instead of needing a maintenance script, all it will take to re-secure the database after a leak would be for the sysadmin to run `UPDATE user SET user_token = NULL;` and user tokens will be regenerated as needed.
r110825