SessionSentry models rotation, idle and absolute expiry, explicit revocation, stale-token replay, and CSRF checks for state-changing requests. The goal is to make the server-side decisions visible rather than reduce session security to a cookie checklist.
This is a defensive teaching model. It does not implement real cookies, encryption, browser SameSite behavior, OAuth/OIDC, credential storage, or production identity infrastructure. Source and tests ↗