Repository navigation
fix(backend): await session destroy before logout response - #1721
Conversation
Closes #1623 Wraps req.session.destroy() in a Promise and awaits it before sending the logout response. This ensures the session is fully destroyed before the client receives the success response, preventing a race condition where rapid logout→login sequences could operate on a session that hasn't been fully destroyed yet. If session.destroy() fails, the error is now properly rejected and handled by asyncHandler instead of being silently logged.
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 15 minutes Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Failed to generate code suggestions for PR |
|
There was a problem hiding this comment.
No issues found across 1 file
Auto-approved: Wraps session.destroy in a Promise and awaits it to prevent race conditions on logout.
Re-trigger cubic
|
🤖 I have created a release *beep* *boop* --- <details><summary>2.33.1</summary> ## [2.33.1](v2.33.0...v2.33.1) (2026-07-09) ### Bug Fixes * **backend:** await session destroy before logout response ([#1721](#1721)) ([b1f0c19](b1f0c19)) * **docker:** chown [@prisma](https://github.com/prisma) so bot can write migrate engine ([#1734](#1734)) ([#1735](#1735)) ([901e0fd](901e0fd)) * update CONTEXT.md reference in domain.md ([#1744](#1744)) ([c92aa26](c92aa26)) * **webhook:** add curl to webhook container ([#1742](#1742)) ([50d9500](50d9500)) </details> --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).



Closes #1623
Description
Wraps `req.session.destroy()` in a Promise and awaits it before sending the logout response. This ensures the session is fully destroyed before the client receives the success response, preventing a race condition where rapid logout→login sequences could operate on a session that hasn't been fully destroyed yet.
If session.destroy() fails, the error is now properly rejected and handled by asyncHandler instead of being silently logged.
Testing
Changes Made
Summary by cubic
Ensure logout waits for the session to be fully destroyed before responding, preventing race conditions during rapid logout→login. Errors from
req.session.destroy()now reject and flow to the error handler instead of being silently logged.Written for commit 6d2c49e. Summary will update on new commits.