Skip to content

fix(backend): await session destroy before logout response - #1721

Merged
LucasSantana-Dev merged 2 commits into
mainfrom
fix-1623-session-destroy-v2
Jul 9, 2026
Merged

LucasSantana-Dev merged 2 commits into
mainfrom
fix-1623-session-destroy-v2

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Jul 9, 2026 •

Copy link
Copy Markdown
Owner

Closes #1623

Description

Wraps `req.session.destroy()` in a Promise and awaits it before sending the logout response. This ensures the session is fully destroyed before the client receives the success response, preventing a race condition where rapid logout→login sequences could operate on a session that hasn't been fully destroyed yet.

If session.destroy() fails, the error is now properly rejected and handled by asyncHandler instead of being silently logged.

Testing

  • All auth route tests pass (131 tests)
  • Type checking passes with no errors

Changes Made

  • Modified `/packages/backend/src/routes/auth.ts` logout handler to wrap `session.destroy()` callback in a Promise and await completion before sending the success response
  • If destroy fails, the error is now properly rejected instead of silently logged

Summary by cubic

Ensure logout waits for the session to be fully destroyed before responding, preventing race conditions during rapid logout→login. Errors from req.session.destroy() now reject and flow to the error handler instead of being silently logged.

Written for commit 6d2c49e. Summary will update on new commits.

Review in cubic

Closes #1623

Wraps req.session.destroy() in a Promise and awaits it before sending the logout response.
This ensures the session is fully destroyed before the client receives the success response,
preventing a race condition where rapid logout→login sequences could operate on a session
that hasn't been fully destroyed yet.

If session.destroy() fails, the error is now properly rejected and handled by asyncHandler
instead of being silently logged.
@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 15 minutes

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: c6506cda-4d26-4eb0-be23-09e9053849b6

📥 Commits

Reviewing files that changed from the base of the PR and between a54c81f and 6d2c49e.

📒 Files selected for processing (1)
  • packages/backend/src/routes/auth.ts
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-1623-session-destroy-v2

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@github-actions

github-actions Bot commented Jul 9, 2026 •

Copy link
Copy Markdown
Warnings
⚠️

User-facing change without a CHANGELOG.md update. Add a line under ## [Unreleased] if this should appear in release notes. (Or apply the skip-changelog label if this PR does not affect end users.)

⚠️

Branch fix-1623-session-destroy-v2 doesn't follow the standard prefix convention (feature/, fix/, refactor/, chore/, docs/, ci/, test/, release/).

Generated by 🚫 dangerJS against 6d2c49e

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Auto-approved: Wraps session.destroy in a Promise and awaits it to prevent race conditions on logout.

Re-trigger cubic

@LucasSantana-Dev
LucasSantana-Dev enabled auto-merge (squash) July 9, 2026 03:50
@sonarqubecloud

sonarqubecloud Bot commented Jul 9, 2026

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit b1f0c19 into main Jul 9, 2026
43 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the fix-1623-session-destroy-v2 branch July 9, 2026 13:42
LucasSantana-Dev added a commit that referenced this pull request Jul 9, 2026
🤖 I have created a release *beep* *boop*
---


<details><summary>2.33.1</summary>

##
[2.33.1](v2.33.0...v2.33.1)
(2026-07-09)


### Bug Fixes

* **backend:** await session destroy before logout response
([#1721](#1721))
([b1f0c19](b1f0c19))
* **docker:** chown [@prisma](https://github.com/prisma) so bot can
write migrate engine
([#1734](#1734))
([#1735](#1735))
([901e0fd](901e0fd))
* update CONTEXT.md reference in domain.md
([#1744](#1744))
([c92aa26](c92aa26))
* **webhook:** add curl to webhook container
([#1742](#1742))
([50d9500](50d9500))
</details>

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

M4: session.destroy() unawaited in logout route — potential race condition

1 participant