diff --git a/controllers/auth.js b/controllers/auth.js index ec91b37..08a8677 100644 --- a/controllers/auth.js +++ b/controllers/auth.js @@ -135,10 +135,12 @@ const logout = async (req, res) => { const delSession = req.session.destroy((err) => { if (Object.keys(err).length) { logger.error("Error while logging out", { err }); + return res.sendStatus(500); } else { logger.info("Logged out.", { sessionID: delSession.id }); + res.clearCookie("connect.sid"); + return res.sendStatus(200); } - return res.sendStatus(200); }) } catch (error) { logger.error('logout', { error }); diff --git a/middleware/authCheck.js b/middleware/authCheck.js index 4337550..7ba27bf 100644 --- a/middleware/authCheck.js +++ b/middleware/authCheck.js @@ -13,12 +13,14 @@ const isAuthenticated = (req, res, next) => { next() } else { const delSession = req.session.destroy((err) => { - if (err) { + if (Object.keys(err).length) { logger.error("Error while destroying session.", { err }); + return res.status(500).send("Server error, try later."); } else { - logger.info("Session destroyed.", { sessionID: delSession.id }); + logger.info("Session invalid, destroyed.", { sessionID: delSession.id }); + res.clearCookie("connect.sid"); + return res.sendStatus(401); } - return res.sendStatus(401); }); } }