Why this matters
Strong session controls reduce unauthorized access and meet SOC 2 security criteria.
Set session idle timeout ≤ 15 minutes and absolute timeout ≤ 12 hours; cookies must be Secure, HttpOnly, and SameSite=Lax or Strict; revoke sessions on password change.
Strong session controls reduce unauthorized access and meet SOC 2 security criteria.
Side-by-side examples engineers can pattern-match during review.
Set-Cookie: sid=abcSet-Cookie: sid=abc; Secure; HttpOnly; SameSite=Strictsession.setIdleTimeout(15 * MINUTE)session.setIdleTimeout(0)From the same buckets as this rule.
Public services must require TLSv1.2 or higher and set HSTS (max-age ≥ 15552000, includeSubDomains). Reject plaintext HTTP and weak ciphers; cookies must be Secure and HttpOnly with SameSite set.