fix(09): WR-14 let logout revoke an expired token that is still refreshable and always clear the cookie
This commit is contained in:
@@ -35,7 +35,9 @@ var phase09Routes = []adminRoute{
|
||||
{key: "POST /auth/login", public: true},
|
||||
{key: "POST /auth/refresh", public: true},
|
||||
{key: "GET /lang", public: true},
|
||||
{key: "POST /auth/logout"},
|
||||
// Logout verifies the token itself (exp unchecked, so an expired but
|
||||
// refreshable token can be revoked) and is therefore not behind the guard.
|
||||
{key: "POST /auth/logout", public: true},
|
||||
{key: "GET /auth/me"},
|
||||
{key: "GET /navigation"},
|
||||
{key: "GET /settings"},
|
||||
|
||||
Reference in New Issue
Block a user