Refresh Token Rotation

Student Admin Portal Security Architecture

CLIENT ENVIRONMENT APPLICATION SERVER DATABASE LAYER SECURITY STATE POST /REF SET-COOKIE UPDATE VERIFY REVOKE FAMILY CLIENT PORTAL • Memory: accessToken • Cookie: refreshToken (httpOnly, Secure, SameSite) • Event: Token Expiry • Action: Request Rotation AUTH CONTROLLER • Endpoint: /auth/refresh • Action: Bcrypt Compare • Security: Replay Detection • Flow: Invalidate Current • Reissue: Sign New Pair USER DOCUMENT • Document: Student Record • Array: refreshTokens[] • Storage: Hashed Seeds • Index: ExpiresAt (TTL) • Mutation: Atomic Replace THREAT STATES • Valid Token: Allowed • Stale Token: Used Already • Revoked: Family Dropped • Replay: Trigger Block