fix(09): WR-14 let logout revoke an expired token that is still refreshable and always clear the cookie
This commit is contained in:
@@ -10,7 +10,7 @@ The admin keeps WinterCMS's backend user model: the `backend_users` and `backend
|
||||
|
||||
## Signing in
|
||||
|
||||
`POST <prefix>/api/v1/auth/login` checks the login and password against `backend_users` and issues a JWT for the admin audience, signed with `admin.jwt.secret`. Login attempts are throttled per `admin.login.max_attempts` and `admin.login.decay_minutes`. `POST .../auth/refresh` reissues a token inside the refresh window, and `POST .../auth/logout` revokes the current token by blacklisting its ID in `backend_jwt_blacklist`.
|
||||
`POST <prefix>/api/v1/auth/login` checks the login and password against `backend_users` and issues a JWT for the admin audience, signed with `admin.jwt.secret`. Login attempts are throttled per `admin.login.max_attempts` and `admin.login.decay_minutes`. `POST .../auth/refresh` reissues a token inside the refresh window, and `POST .../auth/logout` revokes the current token by blacklisting its ID in `backend_jwt_blacklist`. Logout accepts a token whose access lifetime has run out as long as its refresh window is open, because `.../auth/refresh` would still accept it, and it always clears the session cookie.
|
||||
|
||||
The admin API accepts the token two ways:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user