vulns.co
/
GKData.io MCP
ID / Identity

Session, cookies, and passkeys

Assess session issuance, recovery, revocation, and privilege changes as one continuous account-authority lifecycle.

Guide 03 / 154 review notesUpdated 2026-10-11

The review

What to look for

Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.

  1. Inventory authority

    Identify the server-recognized session, its binding attributes, expiry, rotation, and the events that should revoke it.

  2. Map transitions

    Review login, recovery, credential change, role change, and logout for consistent reauthentication and invalidation rules.

  3. Check parallel state

    Confirm the same revocation rules reach browser sessions, APIs, and persistent connections.

  4. Review recovery proof

    Ensure account recovery establishes ownership without leaving older authority usable.

What to produce

  • Session lifecycle map
  • Revocation expectations
  • Recovery control notes

Common mistakes

  • Treating logout as a client-only event
  • Ignoring active sessions after recovery
  • Confusing encryption with token authenticity

Continue the study

Reading & source context

Editorial notes above connect these references. Open each record for its original source and review date.

Visual models

Connected disclosures

From the field toolkit

Guide by GK Data · Research snapshot 2026-10-04.
Sources and review dates are preserved in the library provenance.

Next skillOAuth, DPoP, and mix-up →