aegis-auth
Version:
A credentials-based auth solution for Next.js (and other Node projects) with IP rate-limiting, account lockouts, and sessions in DB.
46 lines • 1.53 kB
JavaScript
import { ErrorCodes } from "../types/errorCodes";
import { revokeAllSessionsForUserSchema } from "../validations";
export async function revokeAllSessionsForUser(context, input) {
const { prisma, config } = context;
try {
const validatedInput = revokeAllSessionsForUserSchema.safeParse(input);
if (!validatedInput.success) {
config.logger.securityEvent("INVALID_INPUT", {
route: "revokeAllSessionsForUser",
});
return {
success: false,
status: 400,
message: "Invalid input provided",
code: ErrorCodes.INVALID_INPUT,
};
}
const { userId } = validatedInput.data;
await prisma.session.updateMany({
where: {
userId: userId,
isRevoked: false,
},
data: { isRevoked: true },
});
config.logger.securityEvent("ALL_SESSIONS_REVOKED", { userId });
return {
success: true,
status: 200,
message: "All sessions revoked for user",
};
}
catch (err) {
config.logger.error("Failed to revoke all sessions", {
userId: input.userId,
error: err,
});
return {
success: false,
status: 500,
message: "Failed to revoke sessions",
code: ErrorCodes.INTERNAL_SERVER_ERROR,
};
}
}
//# sourceMappingURL=revokeAllSessionsForUser.js.map