← Inspection rules
SEC-003 / v1.2.0 / 2026-10-02
Inspect endpoints and session revocation
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Environments where endpoints or support files can expose authenticated sessions.
Where to look first
- Endpoint management and SSO session policies
- HAR/support attachments and logout handlers
Inspection steps
- Verify sanitization of cookies, Authorization headers, and personal data before sending HAR files; never output values.
- Inspect revocation, reauthentication, and administrator-session limits; verify old sessions cannot continue acting.
Remediation direction
- Strengthen managed endpoints and session controls; revoke suspected sessions within granted authority.
Evidence required for completion
- Record rejection of synthetic revoked sessions and attachment sanitization checks.
Limits and unverified scope
- A repository cannot establish endpoint health. Cookie flags alone do not establish resistance to endpoint malware.