fix(auth): revoke JWT on logout and harden Google sign-in
Logout now increments sessionVersion so existing JWTs are rejected server-side, deletes orphaned DB sessions, and uses redirectTo for signOut. Google OAuth requests account selection each time; optional AUTH_GOOGLE_PROMPT=login forces Google re-authentication on shared devices. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -24,6 +24,7 @@ NEXTAUTH_URL="http://localhost:3000"
|
||||
# Authorized redirect URI: {NEXTAUTH_URL}/api/auth/callback/google
|
||||
# AUTH_GOOGLE_ID="....apps.googleusercontent.com"
|
||||
# AUTH_GOOGLE_SECRET="GOCSPX-..."
|
||||
# AUTH_GOOGLE_PROMPT="select_account" # or "login" to force Google password every time
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# AI Providers
|
||||
|
||||
Reference in New Issue
Block a user