A short explanation for how to properly logout using PassportJs, Express-Session for single page web application.  This short tutorial will share how to fully logout server side and clear the client side cookie as well.

The short answer:

/*** LOGOUT A USER ***/
app.post('/api/logout', (req, res, next) => {
    res.clearCookie('connect.sid');  // clear the session cookie
    req.logout(function(err) {  // logout of passport
        req.session.destroy(function (err) { // destroy the session
            res.send(); // send to the client
        });
    });
});

A thorough explanation:

While the documentation for PassportJs and Express Session are relatively clear for login in a user, I could not find great documentation for how these all worked together to logout a user.  Hence, I'm not sure if the above is the official and proper way to logout, and only arrived at this by much trial and error.  My goal was to clear the session on both the server and client.  So, I'll walk you through a short summary of my tests and findings! 🤓

Logging out with the PassportJs logout function

app.post('/logout', function(req, res, next){
  req.logout(function(err) {
    if (err) { return next(err); }
    res.redirect('/');
  });
});

PassportJs provides the example above, but this won't work for my single page web app, as I want to avoid using res.redirect('/'). So below is my first re-write:

/*** LOGOUT A USER ***/
app.post('/api/logout', (req, res, next) => {
    req.logout(function(err) {
        console.log(err)
    });
});

Using req.logout will logout the user and clear the cookie on our database, but it does not clear that pesky cookie on the client.  You can find this cookie by opening google developer console in your browser and clicking the applications tab.

Adding ExpressJs Clear Cookie and sending

Next, I am adding res.clearCookie() provided by ExpressJs.  I am also creating an empty send response to update our client (see code comments below):


/*** LOGOUT A USER ***/
app.post('/api/logout', (req, res, next) => {
    res.clearCookie('connect.sid');  // clear the cookie
    req.logout(function(err) {
        console.log(err)
        res.send(); // send to the client
    });
});

Interestingly, this also clears the cookie on the database, but just keeps updating our client side cookie to something new?

Finally, let's Destroy the Session in Express-Session

Express-session has a function to destroy our session.  Let's then destroy our session prior to sending to the client, as shown in the commented code below.

/*** LOGOUT A USER ***/
app.post('/api/logout', (req, res, next) => {
    res.clearCookie('connect.sid');
    req.logout(function(err) {
        console.log(err)
        req.session.destroy(function (err) { // destroys the session
            res.send();
        });
    });
});

After firing up our server again, we see that the above code clears the session in our database.  It also clears our cookie client side (Hooray!).

Disqus Recommendations

We were unable to load Disqus Recommendations. If you are a moderator please see our troubleshooting guide.

❮

  • 3 years ago

After a month of coding on my new Pixelbook, I'm ready to share how this …

  • 3 years ago

A starter example tutorial for connecting ExpressJs to a Mongoose database …

  • 3 years ago

This tutorial will teach you how to create signup and login functionality on an …

  • 2 years ago

How to fix a "Permission Denied (publickey)" error for Digital Ocean, by …

  • 3 years ago

AI is hot these days, and OpenAI has an excellent and powerful API for all to …

  • 3 years ago

A hackers introductory guide to using chrome developer tools to inspect, …

  • 2 years ago

A fast and simple guide for getting WordPress running locally on a Chromebook …

  • 3 years ago

A deep dive into Mongoose populate, to help avoid some pitfalls that you may …

❯

Disqus Comments

We were unable to load Disqus. If you are a moderator please see our troubleshooting guide.

G

Start the discussion…

Comment

Log in with
or sign up with Disqus or pick a name

Disqus is a discussion network

  • Don't be a jerk or do anything illegal. Everything is easier that way.

Read full terms and conditions

This comment platform is hosted by Disqus, Inc. I authorize Disqus and its affiliates to:

  • Use, sell, and share my information to enable me to use its comment services and for marketing purposes, including cross-context behavioral advertising, as described in our Terms of Service and Privacy Policy, including supplementing that information with other data about me, such as my browsing and location data.
  • Contact me or enable others to contact me by email with offers for goods or services
  • Process any sensitive personal information that I submit in a comment. See our Privacy Policy for more information

Acknowledge I am 18 or older

Favoriting means this is a discussion worth sharing. It gets shared to your followers' Disqus feeds, and gives the creator kudos!

Find More Discussions

Share

  • Tweet this discussion

    • Share this discussion on Facebook
    • Share this discussion via email
    • Copy link to discussion
  • Best

Be the first to comment.

Load more comments

live.rezync.com

live.rezync.com is blocked

This page has been blocked by an extension

  • Try disabling your extensions.

ERR_BLOCKED_BY_CLIENT

Reload

This page has been blocked by an extension

pippio.com

pippio.com is blocked

This page has been blocked by an extension

  • Try disabling your extensions.

ERR_BLOCKED_BY_CLIENT

Reload

This page has been blocked by an extension

Initial Apps](/content/site-root.html)

—

How to Properly Logout using PassportJs, Express-Session, on a Single Page App

Share this