Move invalidate refresh token to TokenManager

This commit is contained in:
advplyr 2025-07-11 14:43:07 -05:00
parent d3402e30c2
commit 7d6d3e6687
2 changed files with 23 additions and 9 deletions

View file

@ -1,5 +1,4 @@
const { Request, Response, NextFunction } = require('express')
const { rateLimit } = require('express-rate-limit')
const passport = require('passport')
const JwtStrategy = require('passport-jwt').Strategy
const ExtractJwt = require('passport-jwt').ExtractJwt
@ -466,14 +465,7 @@ class Auth {
// Invalidate the session in database using refresh token
if (refreshToken) {
try {
Logger.info(`[Auth] logout: Invalidating session for refresh token: ${refreshToken}`)
await Database.sessionModel.destroy({
where: { refreshToken }
})
} catch (error) {
Logger.error(`[Auth] Error destroying session: ${error.message}`)
}
await this.tokenManager.invalidateRefreshToken(refreshToken)
} else {
Logger.info(`[Auth] logout: No refresh token on request`)
}