Replies: 2 comments
|
Hi mike, thanks for bringing up this one. @alicanerdurmaz debugged this and we believe we should not only invalidate auth store but, clear entire store here: https://github.com/refinedev/refine/blob/main/packages/core/src/hooks/auth/useLogout/index.ts#L90 https://tanstack.com/query/v5/docs/reference/QueryClient#queryclientclear |
|
Your issue stems from client-side caching (browser/state management) of data fetched with User1's permissions, which isn't being properly invalidated or cleared for User2. To fix this, clear frontend state (like Redux/Vuex/React Context) on logout, implement robust backend authorization checks (not just UI hiding), and add cache-busting headers or unique request parameters for sensitive data to force re-fetching after login. Your current logout function only redirects, it doesn't clear the application's internal memory where the data resides, so you need to explicitly dispatch a "clear state" action. |
Uh oh!
There was an error while loading. Please reload this page.
Hello,
I am having an issue with data persisting between separate user sessions. For example:
Not only is user2 able to access data they do not have permissions for, the data is persisted outside of ANY authenticated session.
I am sure I am missing something. How can I ensure that all data is cleared on log out? I am using the below right now in my custom
authProviderbut it seems like a bit of a hack.All reactions