diff --git a/assets/openapi.json b/assets/openapi.json
index 6a5298b..31f9559 100644
--- a/assets/openapi.json
+++ b/assets/openapi.json
@@ -7078,6 +7078,103 @@
"$ref": "#/components/schemas/ApplicationCommandCreateSchema"
}
},
+ "SessionsLogoutSchema": {
+ "type": "object",
+ "properties": {
+ "session_ids": {
+ "type": "array",
+ "items": {
+ "type": "string"
+ }
+ },
+ "session_id_hashes": {
+ "type": "array",
+ "items": {
+ "type": "string"
+ }
+ }
+ }
+ },
+ "GetSessionsResponse": {
+ "type": "object",
+ "properties": {
+ "user_sessions": {
+ "type": "array",
+ "items": {
+ "type": "object",
+ "properties": {
+ "id_hash": {
+ "type": "string"
+ },
+ "approx_last_used_time": {
+ "type": "string"
+ },
+ "client_info": {
+ "type": "object",
+ "properties": {
+ "client": {
+ "type": "string"
+ },
+ "os": {
+ "type": "string"
+ },
+ "version": {
+ "type": "integer"
+ },
+ "location": {
+ "type": "string"
+ }
+ },
+ "additionalProperties": false,
+ "required": [
+ "client",
+ "location",
+ "os",
+ "version"
+ ]
+ },
+ "id": {
+ "type": "string"
+ },
+ "status": {
+ "type": "string"
+ },
+ "activities": {
+ "type": "array",
+ "items": {
+ "type": "array",
+ "items": {
+ "$ref": "#/components/schemas/Activity"
+ }
+ }
+ },
+ "client_status": {
+ "$ref": "#/components/schemas/ClientStatus"
+ },
+ "last_seen": {
+ "type": "string",
+ "format": "date-time"
+ },
+ "last_seen_ip": {
+ "type": "string"
+ },
+ "last_seen_location": {
+ "type": "string"
+ }
+ },
+ "additionalProperties": false,
+ "required": [
+ "approx_last_used_time",
+ "client_info",
+ "id_hash"
+ ]
+ }
+ }
+ },
+ "required": [
+ "user_sessions"
+ ]
+ },
"ApplicationCommandOption": {
"type": "object",
"properties": {
@@ -23716,6 +23813,57 @@
]
}
},
+ "/auth/sessions/": {
+ "get": {
+ "security": [
+ {
+ "bearer": []
+ }
+ ],
+ "responses": {
+ "200": {
+ "description": "",
+ "content": {
+ "application/json": {
+ "schema": {
+ "$ref": "#/components/schemas/GetSessionsResponse"
+ }
+ }
+ }
+ }
+ },
+ "tags": [
+ "auth"
+ ]
+ }
+ },
+ "/auth/sessions/logout": {
+ "post": {
+ "security": [
+ {
+ "bearer": []
+ }
+ ],
+ "requestBody": {
+ "required": true,
+ "content": {
+ "application/json": {
+ "schema": {
+ "$ref": "#/components/schemas/SessionsLogoutSchema"
+ }
+ }
+ }
+ },
+ "responses": {
+ "204": {
+ "description": "No description available"
+ }
+ },
+ "tags": [
+ "auth"
+ ]
+ }
+ },
"/auth/reset/": {
"post": {
"requestBody": {
diff --git a/assets/schemas.json b/assets/schemas.json
index eed813e..643cd51 100644
--- a/assets/schemas.json
+++ b/assets/schemas.json
@@ -7532,6 +7532,107 @@
},
"$schema": "http://json-schema.org/draft-07/schema#"
},
+ "SessionsLogoutSchema": {
+ "type": "object",
+ "properties": {
+ "session_ids": {
+ "type": "array",
+ "items": {
+ "type": "string"
+ }
+ },
+ "session_id_hashes": {
+ "type": "array",
+ "items": {
+ "type": "string"
+ }
+ }
+ },
+ "additionalProperties": false,
+ "$schema": "http://json-schema.org/draft-07/schema#"
+ },
+ "GetSessionsResponse": {
+ "type": "object",
+ "properties": {
+ "user_sessions": {
+ "type": "array",
+ "items": {
+ "type": "object",
+ "properties": {
+ "id_hash": {
+ "type": "string"
+ },
+ "approx_last_used_time": {
+ "type": "string"
+ },
+ "client_info": {
+ "type": "object",
+ "properties": {
+ "client": {
+ "type": "string"
+ },
+ "os": {
+ "type": "string"
+ },
+ "version": {
+ "type": "integer"
+ },
+ "location": {
+ "type": "string"
+ }
+ },
+ "additionalProperties": false,
+ "required": [
+ "client",
+ "location",
+ "os",
+ "version"
+ ]
+ },
+ "id": {
+ "type": "string"
+ },
+ "status": {
+ "type": "string"
+ },
+ "activities": {
+ "type": "array",
+ "items": {
+ "type": "array",
+ "items": {
+ "$ref": "#/definitions/Activity"
+ }
+ }
+ },
+ "client_status": {
+ "$ref": "#/definitions/ClientStatus"
+ },
+ "last_seen": {
+ "type": "string",
+ "format": "date-time"
+ },
+ "last_seen_ip": {
+ "type": "string"
+ },
+ "last_seen_location": {
+ "type": "string"
+ }
+ },
+ "additionalProperties": false,
+ "required": [
+ "approx_last_used_time",
+ "client_info",
+ "id_hash"
+ ]
+ }
+ }
+ },
+ "additionalProperties": false,
+ "required": [
+ "user_sessions"
+ ],
+ "$schema": "http://json-schema.org/draft-07/schema#"
+ },
"ApplicationCommandOption": {
"type": "object",
"properties": {
diff --git a/src/api/routes/auth/sessions.ts b/src/api/routes/auth/sessions.ts
new file mode 100644
index 0000000..2c28353
--- /dev/null
+++ b/src/api/routes/auth/sessions.ts
@@ -0,0 +1,75 @@
+/*
+ Spacebar: A FOSS re-implementation and extension of the Discord.com backend.
+ Copyright (C) 2025 Spacebar and Spacebar Contributors
+
+ This program is free software: you can redistribute it and/or modify
+ it under the terms of the GNU Affero General Public License as published
+ by the Free Software Foundation, either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU Affero General Public License for more details.
+
+ You should have received a copy of the GNU Affero General Public License
+ along with this program. If not, see .
+*/
+import { route } from "@spacebar/api";
+import { createHash } from "node:crypto";
+import { Session, Snowflake } from "@spacebar/util";
+import { Request, Response, Router } from "express";
+import { SessionsLogoutSchema } from "../../../schemas/api/users/SessionsSchemas";
+import { In } from "typeorm";
+const router = Router({ mergeParams: true });
+router.get(
+ "/",
+ route({
+ responses: {
+ 200: {
+ body: "GetSessionsResponse",
+ },
+ },
+ }),
+ async (req: Request, res: Response) => {
+ const { extended = false } = req.params;
+ const sessions = (await Session.find({ where: { user_id: req.user_id, is_admin_session: false } })) as Session[];
+
+ res.json({
+ user_sessions: sessions.map((session) => (extended ? session.getExtendedDeviceInfo() : session.getDiscordDeviceInfo())),
+ });
+ },
+);
+
+router.post(
+ "/logout",
+ route({
+ requestBody: "SessionsLogoutSchema",
+ responses: {
+ 204: {},
+ },
+ }),
+ async (req: Request, res: Response) => {
+ const body = req.body as SessionsLogoutSchema;
+
+ let sessions: Session[] = [];
+ if ("session_ids" in body) {
+ sessions = (await Session.find({ where: { user_id: req.user_id, session_id: In(body.session_ids!) } })) as Session[];
+ }
+
+ if ("session_id_hashes" in body) {
+ const allSessions = (await Session.find({ where: { user_id: req.user_id } })) as Session[];
+ const hashSet = new Set(body.session_id_hashes);
+ const matchingSessions = allSessions.filter((session) => {
+ const hash = createHash("sha256").update(session.session_id).digest("hex");
+ return hashSet.has(hash);
+ });
+ sessions.push(...matchingSessions);
+ }
+
+ for (const session of sessions) {
+ await session.remove();
+ }
+ },
+);
+export default router;
diff --git a/src/schemas/api/users/SessionsSchemas.ts b/src/schemas/api/users/SessionsSchemas.ts
new file mode 100644
index 0000000..35dee7c
--- /dev/null
+++ b/src/schemas/api/users/SessionsSchemas.ts
@@ -0,0 +1,55 @@
+/*
+ Spacebar: A FOSS re-implementation and extension of the Discord.com backend.
+ Copyright (C) 2025 Spacebar and Spacebar Contributors
+
+ This program is free software: you can redistribute it and/or modify
+ it under the terms of the GNU Affero General Public License as published
+ by the Free Software Foundation, either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU Affero General Public License for more details.
+
+ You should have received a copy of the GNU Affero General Public License
+ along with this program. If not, see .
+*/
+
+import { ActivitySchema, Snowflake } from "@spacebar/schemas";
+import { ClientStatus } from "@spacebar/util";
+
+export type SessionsLogoutSchema = { session_ids?: Snowflake[]; session_id_hashes?: string[] };
+export type GetSessionsResponse = { user_sessions: DeviceInfo[]; };
+/*return {
+ id: this.session_id,
+ id_hash: crypto.createHash("sha256").update(this.session_id).digest("hex"),
+ status: this.status,
+ activities: this.activities,
+ client_status: this.client_status,
+ approx_last_used_time: this.last_seen.toISOString(),
+ client_info: {
+ ...this.client_info,
+ location: this.last_seen_location,
+ },
+ last_seen: this.last_seen,
+ last_seen_ip: this.last_seen_ip,
+ last_seen_location: this.last_seen_location,
+ };*/
+export type DeviceInfo = {
+ id_hash: string;
+ approx_last_used_time: string;
+ client_info: {
+ client: string;
+ os: string;
+ version: number;
+ location: string;
+ };
+ id?: string;
+ status?: string;
+ activities?: ActivitySchema["activities"][];
+ client_status?: ClientStatus;
+ last_seen?: Date;
+ last_seen_ip?: string;
+ last_seen_location?: string;
+};
\ No newline at end of file
diff --git a/src/util/entities/Session.ts b/src/util/entities/Session.ts
index 1569543..4ff9e10 100644
--- a/src/util/entities/Session.ts
+++ b/src/util/entities/Session.ts
@@ -87,10 +87,28 @@
client_info: {
os: this.client_info.os,
client: this.client_info.client,
- location: this.last_seen_location
+ location: this.last_seen_location,
},
};
}
+
+ getExtendedDeviceInfo() {
+ return {
+ id: this.session_id,
+ id_hash: crypto.createHash("sha256").update(this.session_id).digest("hex"),
+ status: this.status,
+ activities: this.activities,
+ client_status: this.client_status,
+ approx_last_used_time: this.last_seen.toISOString(),
+ client_info: {
+ ...this.client_info,
+ location: this.last_seen_location,
+ },
+ last_seen: this.last_seen,
+ last_seen_ip: this.last_seen_ip,
+ last_seen_location: this.last_seen_location,
+ };
+ }
}
export const PrivateSessionProjection: (keyof Session)[] = ["user_id", "session_id", "activities", "client_info", "status"];