fix(09): WR-14 let logout revoke an expired token that is still refreshable and always clear the cookie

This commit is contained in:
Jakub Zych
2026-10-01 21:23:42 +02:00
parent c9bb14944a
commit 299d220b51
9 changed files with 157 additions and 9 deletions

View File

@@ -193,13 +193,16 @@ func (s *service) mount(r pact.Router) {
// Bearer body and no cookie is set, so a cross-site post gains nothing.
g.Post("/login", s.login, throttle)
g.Post("/refresh", requireAjax(s.refresh))
// Logout reads and verifies the token itself (see service.logout), so
// it is mounted outside the backend guard, which rejects an expired
// access token that is still refreshable.
g.Post("/logout", requireAjax(s.logout))
})
// The string bundle is public: the login screen needs it before auth.
r.GroupRaw(api, nil, func(g pact.Router) {
g.Get("/lang", s.langBundle)
})
r.GroupRaw(api, []string{"backend"}, func(g pact.Router) {
g.Post("/auth/logout", requireAjax(s.logout))
g.Get("/auth/me", s.me)
g.Get("/navigation", s.navigation)
g.Get("/settings", s.settingsList)