sessions.txt
Review my session handling: <paste>

Check:
- Cookies marked HttpOnly, Secure and SameSite. Say which SameSite
  value and why.
- The session ID regenerated on login — otherwise session fixation
  works.
- Logout invalidates server-side, not just deleting the cookie.
- An absolute maximum lifetime as well as an idle timeout.
- Sessions invalidated on password change.
- What happens across multiple devices — should logging out of one
  affect the others?

Tell me what's currently missing and what each gap allows.

Deleting the cookie is not logging out. If the session is still valid server-side, anyone who captured it still has access.