Skip to content

Clear Session API ​

Overview ​

The clear-session.post.ts endpoint clears all authentication-related cookies, effectively logging out the user.

Endpoint ​

Path: POST /api/auth/clear-session

File: server/api/auth/clear-session.post.ts

Request Body ​

No request body required.

Response ​

typescript
{
  success: boolean
  message?: string     // "Session cleared successfully"
}

Cookies Cleared ​

The endpoint clears three cookies:

  1. auth_token (HTTP-only)

    • Authentication token cookie
    • Set to empty string with maxAge: 0 (immediate expiry)
  2. auth_user (Not HTTP-only)

    • User data cookie
    • Set to empty string with maxAge: 0
  3. currentWorkspace (Not HTTP-only)

    • Current workspace cookie
    • Set to empty string with maxAge: 0

All cookies are cleared with the same security settings:

typescript
{
  httpOnly: true/false,      // Based on cookie type
  secure: isProduction,     // HTTPS only in production
  sameSite: 'lax',          // CSRF protection
  path: '/',                // Site-wide
  maxAge: 0                 // Immediate expiry
}

Usage ​

typescript
const { $api } = useNuxtApp()

// Logout user
try {
  await $api('/api/auth/clear-session', {
    method: 'POST'
  })
  
  // Redirect to login
  await navigateTo('/login')
} catch (error) {
  console.error('Logout failed:', error)
}

Error Handling ​

If an error occurs during cookie clearing, the endpoint throws an error:

typescript
throw createError({
  statusCode: error.statusCode || 500,
  statusMessage: error.statusMessage || 'Failed to clear session'
})

Security Considerations ​

  1. Immediate Expiry: Cookies are set with maxAge: 0 for immediate deletion
  2. All Cookies: Clears all authentication-related cookies
  3. Secure Flag: Maintains secure flag from original cookie settings
  4. Error Handling: Errors are logged but don't expose sensitive information