fix(auth): invalidate session server-side on logout, not just the cookie

/auth/logout previously only cleared the client's cookie, leaving the
session token valid in the sessions table — a stolen cookie captured
before logout would still work afterwards. Add BackendDbInterface#deleteSession
(implemented in SqliteInterface) and call it from the logout route using
the session token from the cookie. Caught by the new auth-http.test.ts
integration test, updated to assert the session is actually invalidated.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit was merged in pull request #2.
This commit is contained in:
2026-07-02 01:43:50 +00:00
co-authored by Claude
parent 4d9a0cf228
commit 73c4b169c5
5 changed files with 18 additions and 1 deletions
+7
View File
@@ -392,6 +392,13 @@ export class SqliteInterface implements BackendDbInterface {
WHERE "uid" = ${{ uuid: uid }}
`);
}
async deleteSession(token: `as_${string}`): Promise<void> {
this.#checkReadonly();
this.#db.run(sql`
DELETE FROM "sessions"
WHERE "token" = ${{ text: token }}
`);
}
#getApikeyByToken(token: `at_${string}`): ClientApikey {
const apikey = selectClientApikey(