Skip to content

Logout

Method

REST method is adopted.

HTTP Method

POST: User logout

Naming Convention

To unify the naming of query parameters and nodes and improve readability, snake_case is used for URIs and JSON nodes in requests.

Request and Response

Headers

Meta information is set in HTTP headers, not in the response body.

Request Headers

  • Authorization
  • Content-Type
  • Accept
  • Accept-language

Response Headers

  • Content-Type

Logout

URI

POST /v1/auth/logout

Request Body

No request body is required.

Response

The response is JSON.

{
  "message": "Successfully logged out"
}

Response Fields

Name Type Description
message string Success message

Authentication

Authentication is performed using JSON Web Tokens (JWT) issued by Amazon Cognito.

A Bearer token is required:

Authorization: Bearer <access_token>

Error Handling

The status codes for error handling are as follows.

Description Status Code Status Name
Token missing or invalid 401 Unauthorized
Internal server error 500 Internal Server Error

Processing Flow

  1. Extract Bearer token from Authorization header
  2. Extract user information from token (via middleware)
  3. Invalidate session in AWS Cognito
  4. Return success message

Detailed Flowchart

flowchart TD
    Start([POST /v1/auth/logout]) --> Middleware[protectedRoute<br/>Middleware]

    Middleware --> ValidateToken[JWT Token Validation]
    ValidateToken --> TokenValid{Valid?}
    TokenValid -->|NG| Err401[401 Unauthorized]
    TokenValid -->|OK| ExtractUser[Extract User Info<br/>Cognito sub]

    ExtractUser --> Route[Route Handler]
    Route --> Service[Service Layer]

    Service --> CognitoLogout[AWS Cognito<br/>Global Sign Out]

    CognitoLogout --> LogoutOK{Successful?}
    LogoutOK -->|NG| Err500[500 Internal Error]
    LogoutOK -->|OK| Success[200 OK<br/>Successfully logged out]

Security

  • Token validation: protectedRoute middleware
  • Session invalidated in Cognito (token becomes unusable)