Password changes invalidate all other sessions, but we should also cycle the current session's id. This will protect against the possibility of someone intercepting session cookies and then you change your password on the current session, so their copy of the cookies will no longer work.
Good fix,
db/8140
is clear to merge.