Webhook: accept trailing-slash target, 401 on bad signature, global_logout ends sessions
POST /webhooks/gnexus-auth/ (the spelling the auth platform had stored)
never redirected: the GET SPA catch-all matched the path and answered
405 allow:GET, so the platform's auth.global_logout deliveries kept
retrying and creds sessions outlived a global logout. Register both
spellings, return 401/400 on signature/payload failures instead of an
unhandled 500, and on auth.global_logout delete every session row of the
targeted user (other users' sessions untouched; API tokens long-lived
by design and revoked explicitly).

Co-Authored-By: Claude Code <noreply@anthropic.com>
1 parent 6761826 commit 27f95b4be1d6f8876a29dd0e8b7481f60c19364f
@Eugene Sukhodolskiy Eugene Sukhodolskiy authored 2 hours ago
Showing 2 changed files
View
gnexus_creds/oauth.py
View
tests/test_auth.py