I search if there is a simple way to allow only one session per account with Symfony 3 ?
For the moment, I use the PdoSessionHandler to store sessions in database, and I've a listener on the onSecurityInteractiveLogin event. When the user is log-in, I set the sessionId in the User object, and persist it in database.
Now, I would like do it: When a user is successfully login, I also inactivate the previous session, but how can I inactivate an other session ? In Symfony I can do it for the actual session, but not for an other...
Else, maybe I can process to a SQL request to delete the previous session, but then, the previous user loose all things stored in the session, I just want disconnect him.
An other way, is the inverse: say to the new user: "A session is actually open with your login, please disconnect from the other machine.", but if the user just close his browser (no click on logout) and comeback some seconds/minutes after with a remember me token, for exemple, he can't be log in... And must wait for several minutes.
If someone have an idea ?