Matthew C.
—When using the Passport.js library for authenticating requests, you may get the following error:
Error: req#logout requires a callback function
If you’re using Passport.js version 0.6.0+, calling the logout()
method synchronously will cause this error:
app.post("/logout", (req, res, next) => { req.logout(); res.redirect("/"); });
As of version 0.6.0, the logout()
method is asynchronous to protect against session fixation attacks. A session fixation attack can only occur if a session ID is “fixed” at the time it is generated. The attacker also needs physical access to the same computer as the victim, unless the app has other security issues such as Cross-Site Scripting (XSS) vulnerabilities or accepting session IDs in URL parameters. The Passport.js version 0.6.0 release fixes the vulnerability by regenerating the session when a user logs in or out, which results in a new session ID.
The Passport.js logout()
method should have a callback function added as an argument if you are using version 0.6.0+:
app.post("/logout", (req, res, next) => { req.logout((err) => { if (err) { return next(err); } res.redirect("/"); }); });
Tasty treats for web developers brought to you by Sentry. Get tips and tricks from Wes Bos and Scott Tolinski.
SEE EPISODESConsidered “not bad” by 4 million developers and more than 100,000 organizations worldwide, Sentry provides code-level observability to many of the world’s best-known companies like Disney, Peloton, Cloudflare, Eventbrite, Slack, Supercell, and Rockstar Games. Each month we process billions of exceptions from the most popular products on the internet.
Here’s a quick look at how Sentry handles your personal information (PII).
×We collect PII about people browsing our website, users of the Sentry service, prospective customers, and people who otherwise interact with us.
What if my PII is included in data sent to Sentry by a Sentry customer (e.g., someone using Sentry to monitor their app)? In this case you have to contact the Sentry customer (e.g., the maker of the app). We do not control the data that is sent to us through the Sentry service for the purposes of application monitoring.
Am I included?We may disclose your PII to the following type of recipients:
You may have the following rights related to your PII:
If you have any questions or concerns about your privacy at Sentry, please email us at compliance@sentry.io.
If you are a California resident, see our Supplemental notice.