Skip to content

revoke-other-sessions issues two queries per revoked session #11433

Description

@TiagoGranelli

Is this suited for github?

  • Yes, this is suited for github

Reproduction

  1. Sign in the same user several times so they have N active sessions.
  2. From one of them, call POST /revoke-other-sessions.
  3. Count the SQL statements (we logged them at the pg client).

With the Drizzle adapter on Postgres we measured 3 statements with no other session and 43 with 20 other sessions, that is 3 + 2N. For comparison, /revoke-sessions stays at 4 and /list-sessions at 3 whatever N is.

Current vs. Expected behavior

revokeOtherSessions (dist/api/routes/session.mjs in 1.7.6) lists the user's sessions and then deletes them one token at a time:

await Promise.all(otherSessions.map((session) => ctx.context.internalAdapter.deleteSession(session.token)))

Each deleteSession is a lookup plus a delete. internalAdapter.deleteSessions(tokens) already exists and deletes with a single token IN (...), handling secondary storage and preserved sessions, so passing the filtered tokens to it would keep the endpoint at a constant number of statements.

What version of Better Auth are you using?

1.7.6

System info

better-auth 1.7.6, @better-auth/drizzle-adapter 1.7.6, drizzle-orm 0.45.3, pg 8.23.0
PostgreSQL 18.6, Node.js 26, Linux x64

Which area(s) are affected?

Backend

Additional context

Found by a test that fails if an endpoint's query count grows with the number of rows.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions