Skip to content

fix(auth): logout revokes the token family (send client_id) - #33

Merged
spacedevin merged 1 commit into
mainfrom
fix/revoke-client-id
Oct 8, 2026
Merged

spacedevin merged 1 commit into
mainfrom
fix/revoke-client-id

Conversation

@spacedevin

Copy link
Copy Markdown
Member

logout() posted only {token: accessToken} to /api/oauth/revoke. The gateway requires client_id (public PKCE clients send no secret), so every logout got 401 and the session's tokens stayed live.

Adds revokeTokens(): sends client_id and the refresh token when present (revokes the whole family — every access token minted from it), else the access token, with token_type_hint. Never throws; logout continues. Tests in src/lib/tests/revoke.test.ts.

@spacedevin
spacedevin merged commit 0430c1d into main Oct 8, 2026
4 checks passed
@spacedevin
spacedevin deleted the fix/revoke-client-id branch October 8, 2026 20:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant