forked from alterminal/alterminal
fixup
This commit is contained in:
+14
-6
@@ -37,12 +37,7 @@ func LogoutHandler(db *gorm.DB) http.HandlerFunc {
|
||||
}
|
||||
}
|
||||
|
||||
if c, err := r.Cookie(CookieName); err == nil {
|
||||
if err := DeleteSession(db, c.Value); err != nil {
|
||||
log.Printf("logout: %v", err)
|
||||
}
|
||||
}
|
||||
clearSessionCookie(w, r)
|
||||
ClearSession(db, w, r)
|
||||
|
||||
if isForm {
|
||||
// PRG:以 303 導向 /login 顯示登入表單,避免重新整理重複送出。
|
||||
@@ -53,6 +48,19 @@ func LogoutHandler(db *gorm.DB) http.HandlerFunc {
|
||||
}
|
||||
}
|
||||
|
||||
// ClearSession 刪除資料庫中的 Session 並清除瀏覽器 Cookie,冪等——查無
|
||||
// Session 亦清除 Cookie;資料庫刪除失敗僅記錄不中斷(Session 最遲於效期
|
||||
// 到期失效)。供 LogoutHandler 與 oidc 套件的 RP-Initiated Logout 端點
|
||||
// 共用同一套清理邏輯。
|
||||
func ClearSession(db *gorm.DB, w http.ResponseWriter, r *http.Request) {
|
||||
if c, err := r.Cookie(CookieName); err == nil {
|
||||
if err := DeleteSession(db, c.Value); err != nil {
|
||||
log.Printf("logout: %v", err)
|
||||
}
|
||||
}
|
||||
clearSessionCookie(w, r)
|
||||
}
|
||||
|
||||
// clearSessionCookie 以 Max-Age=0 清除瀏覽器的 Session Cookie(與
|
||||
// setSessionCookie 對稱,屬性一致以免因 Path 或 Secure 差異清不掉)。
|
||||
func clearSessionCookie(w http.ResponseWriter, r *http.Request) {
|
||||
|
||||
Reference in New Issue
Block a user