Skip to content

Conversation

matheusgalvao1
Copy link
Collaborator

The way we used to logout users using session auth had a flaw that allowed clients with old session cookies to access protected routes, now we are storing a list of invalidated session IDs

@matheusgalvao1 matheusgalvao1 merged commit 3756c9c into main Feb 18, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant