/** * DELETE /_emdash/api/auth/session-tokens/:id * * Revoke one of the caller's own tokens (a session token that is no longer * needed). Session-only, like minting. */ import type { APIRoute } from "astro"; import { requirePerm } from "#api/authorize.js"; import { apiError, unwrapResult } from "#api/error.js"; import { handleApiTokenRevoke } from "#api/handlers/api-tokens.js"; export const prerender = false; export const DELETE: APIRoute = async ({ params, locals }) => { const { emdash, user } = locals; if (!emdash?.db) return apiError("NOT_CONFIGURED", "EmDash is not initialized", 500); if (locals.tokenAuth) { return apiError( "TOKEN_AUTH_FORBIDDEN", "Session tokens can only be revoked from a signed-in session.", 403, ); } const denied = requirePerm(user, "content:edit_own"); if (denied) return denied; const id = params.id ?? ""; if (!id) return apiError("VALIDATION_ERROR", "Token id required", 400); return unwrapResult(await handleApiTokenRevoke(emdash.db, id, user!.id)); };