Web frontend and supporting services for lance.blue
headquarters plan session-security.md
2.7 kB


id: session-security title: A session is only as alive as the grant behind it status: open repos: [headquarters] dependsOn: [sign-in] exitCriterion: > Revoking lance.blue's grant from the player's own PDS signs them out here, and the login path cannot be used to make someone else's server work for us. #

session-security #

These were written down as requirements before sign-in was built, so that sign-in was built against them rather than rediscovering them. None of them were answered. Two related items from elsewhere in the old TODO join them.

The shape of the problem is that a session cookie here and a grant on the player's PDS are two different facts, and only the second one is authoritative.

Already answered, in sign-in #

Key rotation and handle re-verification were part of the same list and are done. Both are described in sign-in, and neither has been exercised against the real event it exists for.

Done #

Nothing in this epic's own list. Two items from the same original requirements set were answered in sign-in and are recorded there: