Passwords use Argon2id and access tokens remain short-lived.
Authentication service, configuration bounds and negative route tests.
Secure password storage prevents neither phishing nor compromised endpoints.
Which access and device controls exist today?
Connect combines memory-hard password hashing with short-lived access tokens, rotating refresh sessions, visible devices and targeted session revocation. FIDO2/WebAuthn credentials can be registered and used for authentication.
Authentication service, configuration bounds and negative route tests.
Secure password storage prevents neither phishing nor compromised endpoints.
Session logic and automated reuse/revocation tests.
An already compromised unlocked endpoint remains a separate risk.
WebAuthn routes, device/session endpoints and management interfaces.
No tenant model, SSO or SCIM provisioning.
Which access and device controls exist today?
Yes. The implementation includes FIDO2/WebAuthn registration, authentication and removal. This is not an external certification of the full authentication model.
Yes. Devices and related sessions can be revoked; the effect should also be exercised in the actual pilot environment.