{
  "slug": "session",
  "name": "Session, cookies, and passkeys",
  "category": "Identity",
  "summary": "Assess session issuance, recovery, revocation, and privilege changes as one continuous account-authority lifecycle.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Session and cookie configuration",
    "Recovery and logout flows",
    "Approved browser sessions"
  ],
  "review": [
    {
      "title": "Inventory authority",
      "body": "Identify the server-recognized session, its binding attributes, expiry, rotation, and the events that should revoke it."
    },
    {
      "title": "Map transitions",
      "body": "Review login, recovery, credential change, role change, and logout for consistent reauthentication and invalidation rules."
    },
    {
      "title": "Check parallel state",
      "body": "Confirm the same revocation rules reach browser sessions, APIs, and persistent connections."
    },
    {
      "title": "Review recovery proof",
      "body": "Ensure account recovery establishes ownership without leaving older authority usable."
    }
  ],
  "outputs": [
    "Session lifecycle map",
    "Revocation expectations",
    "Recovery control notes"
  ],
  "pitfalls": [
    "Treating logout as a client-only event",
    "Ignoring active sessions after recovery",
    "Confusing encryption with token authenticity"
  ],
  "references": {
    "resources": [
      {
        "id": "owasp-session-privilege-transition-integrity",
        "title": "OWASP Session Management: privilege-transition integrity",
        "url": "https://vulns.co/research/resources/owasp-session-privilege-transition-integrity/"
      },
      {
        "id": "owasp-account-recovery-state-integrity",
        "title": "OWASP Forgot Password",
        "url": "https://vulns.co/research/resources/owasp-account-recovery-state-integrity/"
      },
      {
        "id": "usenix-2026-passkey-remediation-authority-lifecycle",
        "title": "Adversarial passkeys: account recovery must close every continuing source of authority",
        "url": "https://vulns.co/research/resources/usenix-2026-passkey-remediation-authority-lifecycle/"
      }
    ],
    "diagrams": [
      {
        "id": "account-recovery-challenge-lifecycle",
        "title": "Recovery must preserve account ownership",
        "url": "https://vulns.co/research/diagrams/account-recovery-challenge-lifecycle/"
      }
    ],
    "reports": [
      {
        "id": "gitlab-recovery-address-binding-cve-2023-7028",
        "title": "GitLab recovery delivery lacked verified-address binding",
        "url": "https://vulns.co/research/reports/gitlab-recovery-address-binding-cve-2023-7028/"
      },
      {
        "id": "microsoft-account-recovery-rate-limit-consistency-2021",
        "title": "Microsoft account recovery lacked consistent attempt-limit enforcement",
        "url": "https://vulns.co/research/reports/microsoft-account-recovery-rate-limit-consistency-2021/"
      },
      {
        "id": "instagram-recovery-challenge-account-binding-2019",
        "title": "Instagram recovery challenges were insufficiently bound to accounts",
        "url": "https://vulns.co/research/reports/instagram-recovery-challenge-account-binding-2019/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/session/",
  "markdown_url": "https://vulns.co/skills/session/SKILL.md"
}
