[E05-S02-T05] Expiration enforced server-side #240

Open
opened 2026-08-27 00:17:20 +00:00 by kpcto · 0 comments
Owner

Parent story: [E05-S02] Opaque DB-backed session (#73)

Intent

Enforce session expiration on the server side.

Acceptance criteria

  • Session expiration is enforced on the server side
  • An expired session is rejected even if the cookie remains present

Explicitly out of scope

  • Token generation (E05-S02-T01)
  • Lookup hash storage (E05-S02-T02)
  • Secure/HttpOnly/SameSite attributes (E05-S02-T03)
  • Logout revocation (E05-S02-T04)
  • Admin API 401 to anonymous caller (E05-S02-T06)

Test plan

  • Automated test advances the clock and asserts an expired session is rejected

Rollback note

  • Revert expiry change; re-login to obtain a fresh session

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E05-S02] Opaque DB-backed session (#73) ## Intent Enforce session expiration on the server side. ## Acceptance criteria - Session expiration is enforced on the server side - An expired session is rejected even if the cookie remains present ## Explicitly out of scope - Token generation (E05-S02-T01) - Lookup hash storage (E05-S02-T02) - Secure/HttpOnly/SameSite attributes (E05-S02-T03) - Logout revocation (E05-S02-T04) - Admin API 401 to anonymous caller (E05-S02-T06) ## Test plan - Automated test advances the clock and asserts an expired session is rejected ## Rollback note - Revert expiry change; re-login to obtain a fresh session ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 1 milestone 2026-08-27 00:17:20 +00:00
kpcto added the
kind
task
status
proposed
labels 2026-08-27 00:17:20 +00:00
Sign in to join this conversation.