[E05-S02] Opaque DB-backed session #73

Open
opened 2026-08-27 00:00:39 +00:00 by kpcto · 0 comments
Owner

Parent epic: [E05] Administrator security (#33)

Intent

Authenticated administrator sessions use opaque DB-backed tokens with hashed storage, production cookie attributes, server-side expiry, revocation on logout, and a 401 for anonymous admin calls.

Acceptance criteria

  • Session token is a random raw value of at least 256 bits
  • Only a lookup hash of the token is stored, never the raw token
  • Session cookie sets Secure, HttpOnly and SameSite attributes in production
  • Logout revokes the server-side session record
  • Session expiration is enforced on the server side
  • Anonymous callers receive a 401 from the admin API

Explicitly out of scope

  • Administrator bootstrap and password handling (E05-S01)
  • CSRF protection on cookie-authenticated state changes (E05-S03)

Test plan

  • Automated tests cover token generation, hashing, expiry and revocation
  • Manual check confirms production cookie flags over HTTPS

Rollback note

  • Delete session rows and redeploy previous session code; no schema change required

Owning stream

platform

Risk quadrant

agent-full

> Parent epic: [E05] Administrator security (#33) ## Intent Authenticated administrator sessions use opaque DB-backed tokens with hashed storage, production cookie attributes, server-side expiry, revocation on logout, and a 401 for anonymous admin calls. ## Acceptance criteria - Session token is a random raw value of at least 256 bits - Only a lookup hash of the token is stored, never the raw token - Session cookie sets Secure, HttpOnly and SameSite attributes in production - Logout revokes the server-side session record - Session expiration is enforced on the server side - Anonymous callers receive a 401 from the admin API ## Explicitly out of scope - Administrator bootstrap and password handling (E05-S01) - CSRF protection on cookie-authenticated state changes (E05-S03) ## Test plan - Automated tests cover token generation, hashing, expiry and revocation - Manual check confirms production cookie flags over HTTPS ## Rollback note - Delete session rows and redeploy previous session code; no schema change required ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 1 milestone 2026-08-27 00:00:39 +00:00
kpcto added the
status
proposed
kind
story
labels 2026-08-27 00:00:39 +00:00
Sign in to join this conversation.