DEFENSIVE AUTHENTICATION LAB

A session is a lifecycle, not just a token.

SessionSentry models rotation, idle and absolute expiry, explicit revocation, stale-token replay, and CSRF checks for state-changing requests. The goal is to make the server-side decisions visible rather than reduce session security to a cookie checklist.

Clock0s
Issued0s
Last seen0s
Revoked tokens0

Session state

Browser token
Copied token
Server current
CSRF token

Decision log

This is a defensive teaching model. It does not implement real cookies, encryption, browser SameSite behavior, OAuth/OIDC, credential storage, or production identity infrastructure. Source and tests ↗