Default behaviour: Revokes the affected session and sends session expired status code as per what is set in the config.yaml file. By default, the status code is 440.
All auth cookies are cleared by the time this function is called, even if you do not use the default one.