Cleanup Sessions
Method
REST method is adopted.
HTTP Method
POST: Expired session cleanup
Naming Convention
To unify the naming of query parameters and nodes and improve readability, snake_case is used for URIs and JSON nodes in requests.
Request and Response
Headers
Meta information is set in HTTP headers, not in the response body.
Request Headers
X-API-KeyContent-TypeAccept
Response Headers
Content-Type
Session Cleanup
URI
Request Body
No request body is required.
Response
The response is JSON.
Response Fields
| Name | Type | Description |
|---|---|---|
| message | string | Success message |
| cleanedCount | number | Number of cleaned up sessions |
Authentication
This endpoint uses API key authentication (not a Bearer token).
Error Handling
The status codes for error handling are as follows.
| Description | Status Code | Status Name |
|---|---|---|
| API key missing or invalid | 401 | Unauthorized |
| Internal server error | 500 | Internal Server Error |
Processing Flow
- Extract X-API-Key from request header
- Validate API key using timing-safe comparison
- Query and delete expired session records
- Return number of cleaned up sessions
Security
- API key required (not a user token)
- Timing-safe comparison prevents timing attacks
- Intended for scheduled execution via AWS EventBridge
- Logs unauthorized access attempts
Usage
This endpoint should be called from a scheduling service (e.g., AWS EventBridge cron job). It is not intended for user access.
Configuration Example
Environment variable:
AWS EventBridge schedule:
Rate: cron(0 0 * * ? *) # Daily at midnight UTC
Target: API Gateway -> /v1/auth/cleanup_sessions
Headers: X-API-Key: ${SESSION_CLEANUP_API_KEY}
Detailed Flowchart
flowchart TD
Start([POST /auth/cleanup_sessions]) --> ValidateKey[X-API-Key Validation<br/>timing-safe comparison]
ValidateKey --> KeyValid{Valid?}
KeyValid -->|NG| Err401[401 Unauthorized]
KeyValid -->|OK| QueryExpired[Find Expired Sessions]
QueryExpired --> DeleteExpired[Delete Expired Sessions]
DeleteExpired --> CountDeleted[Count Deleted]
CountDeleted --> Success[200 OK<br/>cleaned count]