Skip to content

Cleanup Sessions

Method

REST method is adopted.

HTTP Method

POST: Expired session cleanup

Naming Convention

To unify the naming of query parameters and nodes and improve readability, snake_case is used for URIs and JSON nodes in requests.

Request and Response

Headers

Meta information is set in HTTP headers, not in the response body.

Request Headers

  • X-API-Key
  • Content-Type
  • Accept

Response Headers

  • Content-Type

Session Cleanup

URI

POST /v1/auth/cleanup_sessions

Request Body

No request body is required.

Response

The response is JSON.

{
  "message": "Session cleanup completed",
  "cleanedCount": 42
}

Response Fields

Name Type Description
message string Success message
cleanedCount number Number of cleaned up sessions

Authentication

This endpoint uses API key authentication (not a Bearer token).

X-API-Key: <session_cleanup_api_key>

Error Handling

The status codes for error handling are as follows.

Description Status Code Status Name
API key missing or invalid 401 Unauthorized
Internal server error 500 Internal Server Error

Processing Flow

  1. Extract X-API-Key from request header
  2. Validate API key using timing-safe comparison
  3. Query and delete expired session records
  4. Return number of cleaned up sessions

Security

  • API key required (not a user token)
  • Timing-safe comparison prevents timing attacks
  • Intended for scheduled execution via AWS EventBridge
  • Logs unauthorized access attempts

Usage

This endpoint should be called from a scheduling service (e.g., AWS EventBridge cron job). It is not intended for user access.

Configuration Example

Environment variable:

SESSION_CLEANUP_API_KEY=<secure-random-key>

AWS EventBridge schedule:

Rate: cron(0 0 * * ? *)  # Daily at midnight UTC
Target: API Gateway -> /v1/auth/cleanup_sessions
Headers: X-API-Key: ${SESSION_CLEANUP_API_KEY}

Detailed Flowchart

flowchart TD
    Start([POST /auth/cleanup_sessions]) --> ValidateKey[X-API-Key Validation<br/>timing-safe comparison]
    ValidateKey --> KeyValid{Valid?}
    KeyValid -->|NG| Err401[401 Unauthorized]
    KeyValid -->|OK| QueryExpired[Find Expired Sessions]
    QueryExpired --> DeleteExpired[Delete Expired Sessions]
    DeleteExpired --> CountDeleted[Count Deleted]
    CountDeleted --> Success[200 OK<br/>cleaned count]