Passwords use Argon2id and access tokens remain short-lived.
Authentication service, configuration bounds and negative route tests.
Secure password storage prevents neither phishing nor compromised endpoints.
Which access and device controls exist today?
Connect combines Argon2id passwords with short-lived access tokens, rotating refresh sessions, visible devices and targeted session revocation. FIDO2/WebAuthn credentials, email verification, token-bound password recovery, confirmed account deletion, panic mode and duress-password paths are implemented.
Authentication service, configuration bounds and negative route tests.
Secure password storage prevents neither phishing nor compromised endpoints.
Session logic and automated reuse/revocation tests.
An already compromised unlocked endpoint remains a separate risk.
WebAuthn routes, device/session endpoints and management interfaces.
No tenant model, SSO or SCIM provisioning.
Authentication routes, security interfaces and negative tests for verification, reset, deletion, panic, duress authentication, push removal and local browser cleanup.
Server revocation cannot physically erase an endpoint that remains offline or compromised. Local cleanup runs on the next eligible sign-in path, can be blocked by open browser state and reports that condition explicitly.
Which access and device controls exist today?
Yes. The implementation includes FIDO2/WebAuthn registration, authentication and removal. This is not an external certification of the full authentication model.
Yes. Devices and related sessions can be revoked; the effect should be exercised regularly in the actual operating model.