I am using "Remember Me" in my Forms Authentication for my ASP.NET webapp. If I login with valid credentials and select "Remember Me", i can log in and everything is fine. Now if i close the window, open SQL server and change password and then try to open the webapp, it bypasses login process and uses my old cached credentials from "Remember Me" and allows me to log in.
Is that normal behavior? If so, the only thing I can think of is removing "Remember Me" option or using a very short expiration time.
Any suggestions?