Clear oauthproxy session in case the access token is invalid
This commit is contained in:
@@ -55,7 +55,13 @@ function verifySession(req, res, next) {
|
||||
console.error(error);
|
||||
req.authenticated = false;
|
||||
} else if (result.statusCode !== 200) {
|
||||
req.sessionData.accessToken = null;
|
||||
// clear session
|
||||
delete gSessions[req.session.id];
|
||||
|
||||
req.session.id = uuid.v4();
|
||||
gSessions[req.session.id] = {};
|
||||
req.sessionData = gSessions[req.session.id];
|
||||
|
||||
req.authenticated = false;
|
||||
} else {
|
||||
req.authenticated = true;
|
||||
|
||||
Reference in New Issue
Block a user