fix(09): WR-14 let logout revoke an expired token that is still refreshable and always clear the cookie

This commit is contained in:
Jakub Zych
2026-10-01 21:23:42 +02:00
parent c9bb14944a
commit 299d220b51
9 changed files with 157 additions and 9 deletions

View File

@@ -35,7 +35,9 @@ var phase09Routes = []adminRoute{
{key: "POST /auth/login", public: true},
{key: "POST /auth/refresh", public: true},
{key: "GET /lang", public: true},
{key: "POST /auth/logout"},
// Logout verifies the token itself (exp unchecked, so an expired but
// refreshable token can be revoked) and is therefore not behind the guard.
{key: "POST /auth/logout", public: true},
{key: "GET /auth/me"},
{key: "GET /navigation"},
{key: "GET /settings"},