Button to invalidate all existing session #1920
Draft
+45
−0
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Completes #1017
NextAuth hates this one simple trick: we increment a column called sessionRev on User, if it's greater than sessionRev on token, we return an empty session.
Leveraging session polling we can check if the session has a correct sessionRev, comparing it with User's sessionRev.
In exploration
Screenshots
todo: Invalidate sessions obstacle
Additional Context
I got the idea by reading this
And thought: right we do look up the user anyway, we'll look up sessionRev too and give it to token.But before surrendering on this concept, I'm going to explore if there's something feasible keeping the stateless nature of JWT
Checklist
Are your changes backwards compatible? Please answer below:
Yes, sessionRev defaults to 0 if the registered token doesn't have it already
On a scale of 1-10 how well and how have you QA'd this change and any features it might affect? Please answer below:
3, in testing, actually works
For frontend changes: Tested on mobile, light and dark mode? Please answer below:
n/a
Did you introduce any new environment variables? If so, call them out explicitly here:
No
Progress