Skip to content

Logout

Method

REST method is adopted.

HTTP Method

POST: Session invalidation

Naming Convention

To unify naming of query parameters and nodes and improve readability, snake_case is used for URIs and nodes in JSON during requests.

Request and Response

Headers

Meta information is set in HTTP headers rather than in the response body.

Request Headers

  • Authorization: Bearer <access_token>
  • Content-Type: application/json

Response Headers

  • Content-Type: application/json

Logout

URI

/api/v1/auth/logout

Request Body

No request body required.

Response (200 OK)

Response is JSON.

{
  "message": "Successfully logged out"
}

Authentication

Authentication is performed using JSON Web Tokens (JWT) issued by Amazon Cognito. A valid Bearer token is required in the Authorization header.

Exception Handling

Exception handling status codes are as follows.

Description Status Code Status Name
Missing or invalid token 401 Unauthorized
Internal server error 500 Internal Server Error

Process Flow

Sequence Diagram

sequenceDiagram
    participant Client
    participant Middleware as Protected Route Middleware
    participant API as Hono Router
    participant Service as Auth Service
    participant Cognito as AWS Cognito
    participant DB as PostgreSQL Database

    Client->>Middleware: POST /api/v1/auth/logout
    Middleware->>Middleware: Extract Bearer token
    Middleware->>Cognito: Verify JWT token

    alt Token Valid
        Cognito-->>Middleware: Token verified
        Middleware-->>API: Auth info (sub, token)
        API->>Service: logout(access_token)
        Service->>Cognito: globalSignOut(access_token)
        Cognito-->>Service: Signed out
        Service->>DB: Revoke session by token hash
        DB-->>Service: Session revoked
        Service-->>API: Success
        API-->>Client: 200 OK { message }
    else Token Invalid
        Cognito-->>Middleware: Verification failed
        Middleware-->>Client: 401 Unauthorized
    end

Routes Layer

API routing is performed here. The protectedRoute middleware validates the JWT token before the handler executes. The handler extracts the access token and delegates to the auth service.

Source: src/routes/v1/auth.ts:66

Services Layer

This section describes business logic. It calls Cognito's global sign-out to invalidate the token, then marks the session record as revoked in the database.

Source: src/services/auth.ts

Repositories Layer

This section describes access to databases and external services. It handles session lookup by token hash and session revocation.

Source: src/repositories/

Security

  • Token validated by protectedRoute middleware before handler execution
  • Session invalidated in both Cognito and the database
  • Token becomes unusable after logout across all devices