AUTH PATTERNS
You clicked log out.
One of them didn't.
BOTH KEEP YOU LOGGED IN
HTTP forgets you between requests.
What proves you're still logged in?
SESSION
SERVER-SIDE
Delete the record, and the next request is already logged out.
JWT
SELF-CONTAINED
No server record exists, so it stays valid until it expires.
SESSION — it lives on the server.
Logout deletes it.
JWT — it lives in the token.
Logout cannot reach it.
You clicked log out.
One of them didn't.
You'll want this one
when you build log out.