Sessions that behave
Log out should actually log out.
Review my session handling: <paste> Check: - Cookies marked HttpOnly, Secure and SameSite. Say which SameSite value and why. - The session ID regenerated on login — otherwise session fixation works. - Logout invalidates server-side, not just deleting the cookie. - An absolute maximum lifetime as well as an idle timeout. - Sessions invalidated on password change. - What happens across multiple devices — should logging out of one affect the others? Tell me what's currently missing and what each gap allows.
Deleting the cookie is not logging out. If the session is still valid server-side, anyone who captured it still has access.