Logout
Ending a session closes it on the Secrecy servers and wipes the credentials stored in the browser, so the keys are no longer available on the device.
Log the user out
The secrecyClient.logout method closes the current session when called without argument. It also clears the stored session, identities, key pairs and JWT, along with the client caches.
const logout = async (): Promise<boolean> => {
// First we need to check if the secrecyClient is available
if (!secrecyClient) {
return false;
}
try {
// Without argument, the current session is closed
await secrecyClient.logout();
return true;
} catch (error) {
console.error(error);
return false;
}
};After a logout, the client is no longer usable. Start a new
login to
get an authenticated client again.
Close another session
Passing a session identifier closes that session only, and leaves the local credentials untouched. This is how a user revokes a session opened on another device.
const closeSession = async (sessionId: string): Promise<boolean> => {
// First we need to check if the secrecyClient is available
if (!secrecyClient) {
return false;
}
try {
await secrecyClient.logout(sessionId);
return true;
} catch (error) {
console.error(error);
return false;
}
};React to an expired session
When the server answers an UNAUTHORIZED or FORBIDDEN error, the client logs the user out on its own and reloads the page. The onAccessDenied option lets you run your own handling instead, for example redirecting to your login screen. See the errors page for the full list of error codes.