In this file: https://github.com/Datawheel/macromarket/blob/master/api/auth.js After pw has changed, call: `req.session.destroy();` and require user to log in again.