#60 API: Terminate Session
Description
EditImplement endpoint to terminate a specific session.
Endpoint: DELETE /api/v1/sessions/{session_id}
Response: Success confirmation
Required Permissions: tenant_admin, or session owner
Implementation Requirements:
- Validate session exists
- Prevent terminating own current session without confirmation
- Invalidate JWT associated with session
- Log termination in audit trail
- Notify user via email (optional setting)
Security:
- Cannot terminate system_admin sessions without system_admin role
- Rate limit: 10 per minute
With ultra attention to details and correctness.
Before closing: write comment summarizing implementation with screenshot.
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...