Skip to content
FixedAgent-ready

Signing out other sessions rejects an invalid session id instead of failing

DELETE /api/user/sessions answers 400 for a currentSessionId that is not a session id, instead of a 500.

DELETE /api/user/sessions passed currentSessionId straight to the database, so a value that is not a UUID failed there and answered 500. It now answers 400 "Invalid session ID format" without touching any session, the same as DELETE /api/user/sessions/{sessionId}.