Refresh Token Rotation
Student Admin Portal Security Architecture
Pause Flow
Next Step
Threat Mode: Off
Reset
CLIENT ENVIRONMENT
APPLICATION SERVER
DATABASE LAYER
SECURITY STATE
POST /REF
SET-COOKIE
UPDATE
VERIFY
REVOKE FAMILY
STALE TOKEN REPLAY
CLIENT PORTAL
• Memory: accessToken
• Cookie: refreshToken
(httpOnly, Secure, SameSite)
• Event: Token Expiry
• Action: Request Rotation
AUTH CONTROLLER
• Endpoint: /auth/refresh
• Action: Bcrypt Compare
• Security: Replay Detection
• Flow: Invalidate Current
• Reissue: Sign New Pair
USER DOCUMENT
• Document: Student Record
• Array: refreshTokens[]
• Storage: Hashed Seeds
• Index: ExpiresAt (TTL)
• Mutation: Atomic Replace
THREAT STATES
• Valid Token: Allowed
• Stale Token: Used Already
• Revoked: Family Dropped
• Replay: Trigger Block