Skip to content
Snippets Groups Projects
Commit af7ed8e1 authored by dklug's avatar dklug
Browse files

Return 401 for invalid access_token on logout


Signed-off-by: default avatarDuncan Klug <dklug@ucmerced.edu>
parent 6619f047
No related branches found
No related tags found
No related merge requests found
......@@ -44,7 +44,10 @@ class LogoutRestServlet(ClientV1RestServlet):
requester = yield self.auth.get_user_by_req(request)
except AuthError:
# this implies the access token has already been deleted.
pass
defer.returnValue((401, {
"errcode": "M_UNKNOWN_TOKEN",
"error": "Access Token unknown or expired"
}))
else:
if requester.device_id is None:
# the acccess token wasn't associated with a device.
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment