fix(09): WR-14 let logout revoke an expired token that is still refreshable and always clear the cookie

This commit is contained in:
Jakub Zych
2026-10-01 21:23:42 +02:00
parent c9bb14944a
commit 299d220b51
9 changed files with 157 additions and 9 deletions

View File

@@ -88,6 +88,7 @@ func Login(secret string) (string, error) {
| `bouncer.VerifyClaimsAudience` | `bouncer.VerifyClaims` with a required audience. |
| `bouncer.Refresh` | Reissues a frontend token inside the refresh window and blacklists the old jti. |
| `bouncer.RefreshAudience` | Refresh for a token that carries the given audience. |
| `bouncer.VerifyRefreshableClaimsAudience` | Verifies signature and audience without checking `exp`, while the refresh window is open; for revoking a refreshable token on logout. |
| `bouncer.RefreshAudienceFor` | `bouncer.RefreshAudience` plus the guard's user checks. |
| `bouncer.ErrSubjectRejected` | The token subject is not a loadable user, or the token predates the user's cutoff. |
| `bouncer.AudienceUser`, `bouncer.AudienceBackend` | The frontend and admin audience values. |