Appearance
Clear Session API ​
Overview ​
The clear-session.post.ts endpoint clears all authentication-related cookies, effectively logging out the user.
Endpoint ​
Path: POST /api/auth/clear-session
File: server/api/auth/clear-session.post.ts
Request Body ​
No request body required.
Response ​
typescript
{
success: boolean
message?: string // "Session cleared successfully"
}Cookies Cleared ​
The endpoint clears three cookies:
auth_token (HTTP-only)
- Authentication token cookie
- Set to empty string with
maxAge: 0(immediate expiry)
auth_user (Not HTTP-only)
- User data cookie
- Set to empty string with
maxAge: 0
currentWorkspace (Not HTTP-only)
- Current workspace cookie
- Set to empty string with
maxAge: 0
Cookie Configuration ​
All cookies are cleared with the same security settings:
typescript
{
httpOnly: true/false, // Based on cookie type
secure: isProduction, // HTTPS only in production
sameSite: 'lax', // CSRF protection
path: '/', // Site-wide
maxAge: 0 // Immediate expiry
}Usage ​
typescript
const { $api } = useNuxtApp()
// Logout user
try {
await $api('/api/auth/clear-session', {
method: 'POST'
})
// Redirect to login
await navigateTo('/login')
} catch (error) {
console.error('Logout failed:', error)
}Error Handling ​
If an error occurs during cookie clearing, the endpoint throws an error:
typescript
throw createError({
statusCode: error.statusCode || 500,
statusMessage: error.statusMessage || 'Failed to clear session'
})Security Considerations ​
- Immediate Expiry: Cookies are set with
maxAge: 0for immediate deletion - All Cookies: Clears all authentication-related cookies
- Secure Flag: Maintains secure flag from original cookie settings
- Error Handling: Errors are logged but don't expose sensitive information
Related Documentation ​
- Set Session - Store authentication token
- Get Session - Get session status
- Authentication - Authentication system