IDENTITY SECURITY · LAB
Choose session and token lifetimes, then end access on the server
Set the browser session and access token lifetimes, inspect how the session cookie is protected, and confirm that sign-out and a password change end access on the server, not only in the browser.
Partly readyUses your lab tenant
The lesson
Builds on: Why attackers go after identity.
New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.
Partly ready. Most of this lab runs today. Steps that wait on platform features are marked, and Missing infrastructure says what they need.
- G30 Admin session listing and kill-session
- G42 Session idle timeout (only absolute lifetime today)
Your progress
Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.
Sign in to start this lab and check your progress. Log in or create an account.
Set the browser session lifetime
Recorded as
tenant.oauth.policy.updatesucceeded.Shorten the access token lifetime
Recorded as
tenant.oauth.managers.updatesucceeded.Ava signs out from her account page
Recorded as
account.sign_outsucceeded (signed_out) about[email protected].Set a new password for Ava as administrator
Recorded as
tenant.users.credentials.setsucceeded.The photo API introspects Ava's token after the change
Recorded as
oauth.introspectsucceeded (other_client_token_found) forlab-photo-apiabout[email protected].
Setup
Press Start on this page.
If
lab-photo-apidoes not exist yet, create it in OAuth > Clients: confidential, Resource server on. Copy its secret when it is shown and store both values in your shell, never in a file. The rest of this track uses these two names for the photo API.
export API_ID="<lab-photo-api client ID>"
read -rs API_SECRET
export API_SECRET
Download the lab toolkit if you have not already (see the toolkit page).
btl-lab introspect --client-env APIcalls your tenant's introspection endpoint aslab-photo-api.
Walkthrough
In OAuth > Flow policy, set the browser session lifetime to a value you can defend for this tenant, for example 8 hours (28800 seconds). Save.
Why it matters: a session is a bearer credential. Whoever presents it is treated as the person who signed in, so its lifetime bounds how long any copy stays useful.
In Access Token Management, edit the default access token manager and set the access token lifetime to 10 minutes (600 seconds). Save.
Why it matters: an access token that ends up in a log, a ticket or a chat message stays usable until it expires. A short lifetime is the lesson's main limit on a token that leaks along the way.
Open
$ISSUER/token-decoder, sign in as Ava, and read the access token'siatandexp. They are 600 seconds apart. Copy the access token into your shell without echoing it.
read -rs TOKEN
Why it matters: this confirms the new lifetime reached the runtime. A setting that does not change what is issued protects nothing.
In your browser's developer tools, open the stored cookies for your tenant's host and find
__Host-btl-oauth-session. Note that it isHttpOnly,SecureandSameSite, and that its expiry matches the session lifetime you chose.
Why it matters: these attributes stop scripts in a page reading the cookie and keep it off unencrypted connections. The lesson's point still stands: they are rules for web content, and they do nothing against software running on the device itself, which is why lifetimes and server-side ending matter.
In Logs, source Protocol summaries, find the
oidc.userinfosummary from the Token Decoder's request. It records the operation, outcome, counts and request IDs, and no token or header value.
Why it matters: the Decoder sent the token in an Authorization header, not in the address, and the tenant's records leave credentials out. The lesson shows how a token in a query string ends up in every access log and backup.
Sign out from
$ISSUER/account, then open$ISSUER/accountagain. You are sent to sign in. Now introspect the access token you copied.
btl-lab introspect "$TOKEN" --client-env API
Why it matters: sign-out must end the session on the server, not only clear the browser. The access token is a separate credential, though: it still reports active: true, because ending a browser session is not the same as revoking every token issued from it.
Sign Ava in again at
$ISSUER/account. As Tenant Admin, set a new password for Ava in Users. Refresh Ava's account page: the session has ended. Introspect the token again.
btl-lab introspect "$TOKEN" --client-env API
Why it matters: a credential change ends every session, outstanding code and token the account holds, so introspection now reports active: false. A copy taken before the change is worthless to anyone who checks with the server.
Break it
In OAuth > Flow policy, try to save a browser session lifetime of 60 seconds, then one of 7 days. Both are refused: the tenant accepts 15 minutes to 24 hours. Nothing was saved, so there is nothing to restore.
Check your work
Check my progress confirms the flow policy and token manager changes, Ava's sign-out, the password change, and the photo API's introspection afterwards.
Your notes show the two introspection results:
active: trueafter sign-out,active: falseafter the password change.In Audit, source OAuth management, the token manager update names you as the actor.
Cleanup
Store Ava's new password with
read -rs AVA_PASSWORD.Keep the lifetimes you chose and
lab-photo-api. The next labs use both.Clear the token from your shell with
unset TOKEN.
Missing infrastructure
G30: there is no list of a user's active sessions and no way to end one session from the portal. Once it exists, the lab will sign Ava in from two browsers, find both sessions in Users, end one, and confirm the other keeps working.
G42: sessions have an absolute lifetime only, with no idle timeout, so a session left open on a shared computer lasts its full lifetime. Once it exists, the lab will set a short idle timeout, leave Ava's session untouched, and confirm she must sign in again.