AUTH PATTERNS
You clicked log out.
One of them didn't.
BOTH KEEP YOU LOGGED IN
HTTP forgets you between requests. What proves you're still logged in?
SESSION SERVER-SIDE
BROWSER
holds an ID
API
looks the ID up
STORE
who you are
Delete the record, and the next request is already logged out.
JWT SELF-CONTAINED
BROWSER
holds it all
API
checks the signature
STORE
never asked
No server record exists, so it stays valid until it expires.
SESSION — it lives on the server.
Logout deletes it.
JWT — it lives in the token.
Logout cannot reach it.
You clicked log out.
One of them didn't.
You'll want this one
when you build log out.