fix(09): WR-14 let logout revoke an expired token that is still refreshable and always clear the cookie
This commit is contained in:
@@ -193,13 +193,16 @@ func (s *service) mount(r pact.Router) {
|
||||
// Bearer body and no cookie is set, so a cross-site post gains nothing.
|
||||
g.Post("/login", s.login, throttle)
|
||||
g.Post("/refresh", requireAjax(s.refresh))
|
||||
// Logout reads and verifies the token itself (see service.logout), so
|
||||
// it is mounted outside the backend guard, which rejects an expired
|
||||
// access token that is still refreshable.
|
||||
g.Post("/logout", requireAjax(s.logout))
|
||||
})
|
||||
// The string bundle is public: the login screen needs it before auth.
|
||||
r.GroupRaw(api, nil, func(g pact.Router) {
|
||||
g.Get("/lang", s.langBundle)
|
||||
})
|
||||
r.GroupRaw(api, []string{"backend"}, func(g pact.Router) {
|
||||
g.Post("/auth/logout", requireAjax(s.logout))
|
||||
g.Get("/auth/me", s.me)
|
||||
g.Get("/navigation", s.navigation)
|
||||
g.Get("/settings", s.settingsList)
|
||||
|
||||
Reference in New Issue
Block a user