Logout
Method
REST method is adopted.
HTTP Method
POST: User logout
Naming Convention
To unify the naming of query parameters and nodes and improve readability, snake_case is used for URIs and JSON nodes in requests.
Request and Response
Headers
Meta information is set in HTTP headers, not in the response body.
Request Headers
AuthorizationContent-TypeAcceptAccept-language
Response Headers
Content-Type
Logout
URI
Request Body
No request body is required.
Response
The response is JSON.
Response Fields
| Name | Type | Description |
|---|---|---|
| message | string | Success message |
Authentication
Authentication is performed using JSON Web Tokens (JWT) issued by Amazon Cognito.
A Bearer token is required:
Error Handling
The status codes for error handling are as follows.
| Description | Status Code | Status Name |
|---|---|---|
| Token missing or invalid | 401 | Unauthorized |
| Internal server error | 500 | Internal Server Error |
Processing Flow
- Extract Bearer token from Authorization header
- Extract user information from token (via middleware)
- Invalidate session in AWS Cognito
- Return success message
Detailed Flowchart
flowchart TD
Start([POST /v1/auth/logout]) --> Middleware[protectedRoute<br/>Middleware]
Middleware --> ValidateToken[JWT Token Validation]
ValidateToken --> TokenValid{Valid?}
TokenValid -->|NG| Err401[401 Unauthorized]
TokenValid -->|OK| ExtractUser[Extract User Info<br/>Cognito sub]
ExtractUser --> Route[Route Handler]
Route --> Service[Service Layer]
Service --> CognitoLogout[AWS Cognito<br/>Global Sign Out]
CognitoLogout --> LogoutOK{Successful?}
LogoutOK -->|NG| Err500[500 Internal Error]
LogoutOK -->|OK| Success[200 OK<br/>Successfully logged out]
Security
- Token validation:
protectedRoutemiddleware - Session invalidated in Cognito (token becomes unusable)