[E05-S02-T04] Logout revokes server session #239

Open
opened 2026-08-27 00:17:19 +00:00 by kpcto · 0 comments
Owner

Parent story: [E05-S02] Opaque DB-backed session (#73)

Intent

Logout revokes the server-side session record.

Acceptance criteria

  • Logout revokes the server-side session record
  • A revoked token cannot be reused for an authenticated request

Explicitly out of scope

  • Token generation (E05-S02-T01)
  • Lookup hash storage (E05-S02-T02)
  • Secure/HttpOnly/SameSite attributes (E05-S02-T03)
  • Expiration enforcement (E05-S02-T05)
  • Admin API 401 to anonymous caller (E05-S02-T06)

Test plan

  • Automated test logs out then asserts subsequent request is rejected

Rollback note

  • Revert logout change; any leaked token is invalidated by re-login

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E05-S02] Opaque DB-backed session (#73) ## Intent Logout revokes the server-side session record. ## Acceptance criteria - Logout revokes the server-side session record - A revoked token cannot be reused for an authenticated request ## Explicitly out of scope - Token generation (E05-S02-T01) - Lookup hash storage (E05-S02-T02) - Secure/HttpOnly/SameSite attributes (E05-S02-T03) - Expiration enforcement (E05-S02-T05) - Admin API 401 to anonymous caller (E05-S02-T06) ## Test plan - Automated test logs out then asserts subsequent request is rejected ## Rollback note - Revert logout change; any leaked token is invalidated by re-login ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 1 milestone 2026-08-27 00:17:19 +00:00
kpcto added the
kind
task
status
proposed
labels 2026-08-27 00:17:19 +00:00
Sign in to join this conversation.