When a user logs out in one browser, all other sessions are now revoked on their next page load or token refresh. Adds logged_out_at column to users table, server-side revocation checks on verify/refresh endpoints, and a new /api/session/logout endpoint. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| encryptid | ||
| lib | ||