diff --git a/src/server/connection.rs b/src/server/connection.rs index 7614705fe..cd180ef97 100644 --- a/src/server/connection.rs +++ b/src/server/connection.rs @@ -1206,9 +1206,6 @@ impl Connection { } } video_service::notify_video_frame_fetched_by_conn_id(id, None); - if conn.authorized { - password::update_temporary_password(); - } if let Err(err) = conn.try_port_forward_loop(&mut rx_from_cm).await { conn.on_close(&err.to_string(), false).await; raii::AuthedConnID::check_remove_session(conn.inner.id(), conn.session_key()); @@ -1876,6 +1873,10 @@ impl Connection { } self.authorized = true; self.unauthorized_id = None; + // One-time means gone once it has let a peer in, not once that peer + // leaves. This session's later logins come in on the password the + // session remembers, so they are not affected. + password::update_temporary_password(); // Releases the budget `check_id_whitelist` charges against this address: only a peer // that got this far proved more than a self-reported id. self.clear_id_whitelist_failures();