Remove ability to revoke active session
Session ID is used as a parameter for the revoke session endpoint but it should never be included in the HTML as an attacker could obtain it via XSS.
Showing
![doc/user/profile/img/active_sessions_list.png](https://lab.node.vifib.com/lpgeneau/gitlab-ce/-/raw/44c4aad983570ea1832aa08c39f46dbc1b475fd3/doc/user/profile/img/active_sessions_list.png)
Session ID is used as a parameter for the revoke session endpoint but it should never be included in the HTML as an attacker could obtain it via XSS.
21.7 KB | W: | H:
18.9 KB | W: | H: