Remember Me and Logout

Remembering Users, Logging Out, and Session Invalidation

A true second argument to attempt() or login() stores a random 60-character remember_token and sends a remember_web_<sha1> cookie with the user ID, that token and an HMAC of the password hash, so a password change also kills it. The controller's logout action runs Auth::logout(), $request->session()->invalidate() and $request->session()->regenerateToken().

Remember me, a lost session cookie, and a logoutShell
rm jar; T=$(tok /login)
curl -s $J -o /dev/null -d "_token=$T&$P=correct-horse-9&remember=on" $B/login
awk -v now=$(date +%s) '/remember_web|laravel-session/ {print $5 - now, substr($6, 1, 24)}' jar
sed -i '/laravel-session/d' jar; curl -s $J $B/whoami; echo
X=$(awk '/XSRF-TOKEN/ {print $7}' jar | sed 's/%3D/=/g')
curl -s $J -o /dev/null -w "$W" -H "X-XSRF-TOKEN: $X" -X POST $B/logout
curl -s $J $B/whoami; echo; grep -c remember_web jar
Output
34560000 remember_web_59ba36addc2
7200 laravel-session
{"session":"MmBmcQVC","check":true,"user":"ada@example.com","via_remember":true}
302 http://127.0.0.1:8314/
{"session":"sW8oNFnL","check":false,"user":null,"via_remember":false}
0

The session cookie lasts SESSION_LIFETIME (120 minutes), the remember cookie 400 days. With the session cookie gone, as after closing a browser, Ada was still signed in, and viaRemember() said how. The logout used the XSRF-TOKEN cookie as CSRF proof. logout() expired the cookie and replaced remember_token, so stolen copies die; invalidate() destroyed the session row; and regenerateToken() issued a new CSRF token. Auth::logoutOtherDevices($password) ends all other sessions, given the auth.session middleware.