There is a possible conflict between logout and token prolongation. In the actual example, a new access cookie could be set after the logout request.