Exercise 1: A Real Logout via delete_cookie() — Possible Solution ==================================================================== THE METHOD AND THE ROUTE ------------------------------ def delete_cookie(self, name, path='/'): cookie = SimpleCookie() cookie[name] = '' cookie[name]['path'] = path cookie[name]['max-age'] = 0 self.headers.append(('Set-Cookie', cookie[name].OutputString())) def logout_handler(request): request.state['logged_out'] = True response = Response("logged out") response.delete_cookie('session_id') return response The session middleware itself needs one small change so it doesn't immediately re-set the cookie it was just told to delete: def middleware(request, next_): ... response = next_(request) store.save(sid, request.state['session']) if not request.state.get('logged_out'): response.set_cookie('session_id', sid, max_age=cookie_max_age) return response VERIFIED, REAL RESULT ------------------------------ request 1: b'You have visited 1 times' request 2: b'You have visited 2 times' logging out: b'logged out' cookies jar holds after logout: [] request after logout: b'You have visited 1 times' A real Max-Age=0 Set-Cookie header genuinely causes http.cookiejar to remove the cookie from its own jar entirely - confirmed directly by listing the jar's contents right after the logout request and finding it empty. The very next request has no session_id to send at all, so the middleware creates a real, brand-new session from scratch. WHY THIS WORKS AS AN ANSWER ------------------------------ It reuses set_cookie()'s own SimpleCookie machinery for the opposite job - clearing a cookie is just a Set-Cookie with an empty value and Max-Age=0, no separate mechanism needed - and verifies the real, client-side consequence (the jar actually drops the cookie) rather than only checking the header text was sent correctly.