Cut Auth.js DB load with cached jwtVersion checks, surface Redis in /api/health and deploy warnings, add admin help-center ticket reply UI, rate-limit API tickets/reactions/referral claims, and revoke PATs on sign-out-everywhere. Co-authored-by: Cursor <[email protected]>
41 lines
1.1 KiB
TypeScript
41 lines
1.1 KiB
TypeScript
"use server";
|
|
|
|
import { auth, signOut } from "@/lib/auth";
|
|
import { invalidateJwtVersionCache } from "@/lib/auth/jwt-version-cache";
|
|
import { personalTokenScope } from "@/lib/auth/personal-token-scope";
|
|
import { prisma } from "@/lib/prisma";
|
|
|
|
/**
|
|
* Invalidate every CMS JWT for the signed-in user by bumping website_jwt_version,
|
|
* revoke personal access tokens, then end the current browser session too.
|
|
*/
|
|
export async function signOutEverywhere(): Promise<void> {
|
|
const session = await auth();
|
|
const userId = Number(session?.user?.id);
|
|
if (!Number.isInteger(userId) || userId <= 0) {
|
|
await signOut({ redirectTo: "/login" });
|
|
return;
|
|
}
|
|
|
|
try {
|
|
await prisma.user.update({
|
|
where: { id: userId },
|
|
data: { websiteJwtVersion: { increment: 1 } },
|
|
});
|
|
await invalidateJwtVersionCache(userId);
|
|
} catch {
|
|
/* still continue */
|
|
}
|
|
|
|
// Revoke API bearer tokens (Sanctum / personal_access_tokens).
|
|
try {
|
|
await prisma.personalAccessTokens.deleteMany({
|
|
where: personalTokenScope(userId),
|
|
});
|
|
} catch {
|
|
/* still sign out locally */
|
|
}
|
|
|
|
await signOut({ redirectTo: "/login?signedOutAll=1" });
|
|
}
|