Session Management

Kind: mechanism

Layer: Security Core

Record: architecture:session-management

Severity: contextual

Scope: service, authentication, security

Canonical: Ontology

A mechanism that keeps authenticated sessions on the server, with expiry, rotation and revocation, and gives the client only an opaque identifier.

Listed in Architecture principles, after Parameterized Queries and before Ports and Adapters Architecture.

Requires

Reinforces

Enables

Conflicts with

In tension with

Tensions

Violated by

Severity

Category

Refactors

Linked from