import { json, error } from '@sveltejs/kit'; import type { RequestHandler } from './$types'; import { revokeUserSession } from '$lib/server/pocketbase'; import { log } from '$lib/server/logger'; /** * DELETE /api/sessions/[id] * Revokes a specific session by its PocketBase record ID. * Only the owner can revoke their own sessions. */ export const DELETE: RequestHandler = async ({ params, locals, cookies }) => { if (!locals.user) { error(401, 'Not logged in'); } const recordId = params.id; if (!recordId) { error(400, 'Session ID required'); } try { const ok = await revokeUserSession(recordId, locals.user.id); if (!ok) { error(404, 'Session not found or not yours'); } // If the user is terminating their own current session, clear their auth cookie // so they get logged out immediately (the hook would do this on the next request anyway, // but clearing it here gives instant feedback for the "end this session" flow). // For other sessions, we leave the cookie intact. // We detect "current session" via authSessionId — but since the client sends the // record ID (not the session_id), we rely on the UI to redirect after ending its own session. log.info('sessions', 'session revoked', { recordId, userId: locals.user.id }); return json({ ok: true }); } catch (e) { if (e instanceof Error && 'status' in e) throw e; // re-throw SvelteKit errors log.error('sessions', 'DELETE failed', { recordId, err: String(e) }); error(500, 'Failed to revoke session'); } };