import type {NextRequest} from 'next/server'; import {authApi} from '@/services/api/authApi'; import {proxyUpstream} from '@/shared/services/bff'; export const dynamic = 'force-dynamic'; /** * DELETE /api/auth/sessions/{id} — sign one device out. * * Revoking the CURRENT session is allowed and signs this browser out — which is * a legitimate thing to want and a surprising thing to do by accident, so the * screen warns before calling it rather than this route refusing. */ export async function DELETE( req: NextRequest, {params}: {params: Promise<{id: string}>}, ) { const {id} = await params; return proxyUpstream(req, (token) => authApi.revokeSession(token, id)); }