Logout
Method
REST method is adopted.
HTTP Method
POST: Session invalidation
Naming Convention
To unify naming of query parameters and nodes and improve readability, snake_case is used for URIs and nodes in JSON during requests.
Request and Response
Headers
Meta information is set in HTTP headers rather than in the response body.
Request Headers
Authorization:Bearer <access_token>Content-Type:application/json
Response Headers
Content-Type:application/json
Logout
URI
Request Body
No request body required.
Response (200 OK)
Response is JSON.
Authentication
Authentication is performed using JSON Web Tokens (JWT) issued by Amazon Cognito. A valid Bearer token is required in the Authorization header.
Exception Handling
Exception handling status codes are as follows.
| Description | Status Code | Status Name |
|---|---|---|
| Missing or invalid token | 401 | Unauthorized |
| Internal server error | 500 | Internal Server Error |
Process Flow
Sequence Diagram
sequenceDiagram
participant Client
participant Middleware as Protected Route Middleware
participant API as Hono Router
participant Service as Auth Service
participant Cognito as AWS Cognito
participant DB as PostgreSQL Database
Client->>Middleware: POST /api/v1/auth/logout
Middleware->>Middleware: Extract Bearer token
Middleware->>Cognito: Verify JWT token
alt Token Valid
Cognito-->>Middleware: Token verified
Middleware-->>API: Auth info (sub, token)
API->>Service: logout(access_token)
Service->>Cognito: globalSignOut(access_token)
Cognito-->>Service: Signed out
Service->>DB: Revoke session by token hash
DB-->>Service: Session revoked
Service-->>API: Success
API-->>Client: 200 OK { message }
else Token Invalid
Cognito-->>Middleware: Verification failed
Middleware-->>Client: 401 Unauthorized
end
Routes Layer
API routing is performed here. The protectedRoute middleware validates the JWT token before the handler executes. The handler extracts the access token and delegates to the auth service.
Source: src/routes/v1/auth.ts:66
Services Layer
This section describes business logic. It calls Cognito's global sign-out to invalidate the token, then marks the session record as revoked in the database.
Source: src/services/auth.ts
Repositories Layer
This section describes access to databases and external services. It handles session lookup by token hash and session revocation.
Source: src/repositories/
Security
- Token validated by
protectedRoutemiddleware before handler execution - Session invalidated in both Cognito and the database
- Token becomes unusable after logout across all devices