|
Webhook: accept trailing-slash target, 401 on bad signature, global_logout ends sessions
POST /webhooks/gnexus-auth/ (the spelling the auth platform had stored) never redirected: the GET SPA catch-all matched the path and answered 405 allow:GET, so the platform's auth.global_logout deliveries kept retrying and creds sessions outlived a global logout. Register both spellings, return 401/400 on signature/payload failures instead of an unhandled 500, and on auth.global_logout delete every session row of the targeted user (other users' sessions untouched; API tokens long-lived by design and revoked explicitly). Co-Authored-By: Claude Code <noreply@anthropic.com> |
|---|
|
|
| gnexus_creds/oauth.py |
|---|
| tests/test_auth.py |
|---|