Safeguard
Tag

session-management

Safeguard articles tagged "session-management" — guides, analysis, and best practices for software supply chain and application security.

13 articles

Application Security

The Permission You Just Revoked, According to a Replica That Has Not Heard Yet

A user is removed from a project. The write succeeds on the primary immediately. For the next several hundred milliseconds, a read replica still shows them as a member, and if any authorization check reads from it, they can still act.

Sep 18, 20266 min read
Application Security

A WebSocket Is Authorised Once and Then Lives for Hours

The user is removed from the project, their role is downgraded, their session is revoked. The socket is still open and still receiving, because nothing re-evaluates a connection that was authorised in the past.

Sep 18, 20266 min read
Application Security

Account Recovery Is the Weakest Authentication You Have

You require strong passwords and enforce MFA, then built a flow that lets someone with inbox access bypass all of it. Recovery exists to let in someone who cannot satisfy the normal requirements, so every control above it is capped by how well it is built.

Sep 18, 20266 min read
Application Security

Authenticated DAST: Getting Past the Login Without Wrecking the App

Most of an application is behind a session, so an unauthenticated scan tests the login page and the marketing footer. Getting in is the easy half — staying in, and not clicking Delete Account, is the rest.

Aug 16, 20265 min read
Application Security

Why Math.random() is a security bug waiting to happen

A 2008 Debian OpenSSL patch cut key entropy to ~32,768 values; a 2012 scan found 0.75% of TLS certs shared keys. Weak PRNGs still cause real breaches.

Jul 14, 20266 min read
Application Security

Where should your SPA store auth tokens?

OWASP has warned against localStorage tokens for years, yet it remains the default in countless SPA tutorials — one XSS bug is all it takes to exfiltrate every session.

Jul 10, 20266 min read
AI Security

The Security Chores Agents Should Handle Themselves

Enabling 2FA, rotating a password, revoking a stale session, minting a scoped key — the account-hygiene tasks everyone postpones. When an agent can do them through MCP, 'later' becomes 'now.'

Jul 9, 20264 min read
Application Security

Secure session lifecycle management: tokens, rotation, and cookie flags

OWASP requires session IDs carry at least 64 bits of entropy, yet a 2007 Rails flaw shows one dropped attribute is enough to make fixation trivial.

Jul 8, 20266 min read
Security Guides

OWASP A07: Identification and Authentication Failures — A Deep-Dive Guide

Identification and Authentication Failures rank #7 in the OWASP Top 10 (2021). A deep dive into credential stuffing, session handling, real CVEs, and 2026 fixes.

Jul 5, 20266 min read
Open Source

React Native Cookies: Managing and Securing Session Cookies

A guide to react-native-cookies for reading and writing HTTP cookies in React Native apps, the platform gotchas, and how to keep session cookies secure.

Jun 26, 20265 min read
AppSec

Web Session Security: A Practical Guide

Web session security is the set of controls that keep a logged-in user's session token from being stolen, guessed, or reused by an attacker — and most of it comes down to a handful of cookie flags and lifecycle rules teams routinely skip.

May 8, 20265 min read
Vulnerability Analysis

What is Session Hijacking

Session hijacking lets attackers seize an active, authenticated session and bypass passwords and MFA entirely. Here's how it works and how to stop it.

Mar 26, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.