Evidence review
What to inspect before changing anything
Start with the delivered website and the real user journey. Record the current state so the team can distinguish an observed problem from an assumption and compare the same surface after deployment.
- 01Map every authentication and recovery route
- 02Inspect session lifetime, rotation and revocation
- 03Review brute-force and enumeration responses
Implementation
A practical improvement plan
Make the smallest coherent change that solves the observed problem. Keep normal code review, accessibility, security and product checks in the loop instead of optimizing for the scan alone.
- 01Use established identity libraries or providers
- 02Protect recovery with equivalent assurance
- 03Rotate sessions after privilege changes
Verification
How to verify the result
Verification should test the intended outcome and the most likely regression. Use the production delivery path whenever headers, caching, rendering or third-party services affect the result.
- 01Test valid, invalid, expired and replayed credentials
- 02Confirm logout revokes active sessions
- 03Run account-enumeration checks
Common pitfall
A shortcut to avoid
Hardening only the login form leaves password reset, magic links or session renewal as weaker entry points.
Further reading
Primary guidance and references
These sources provide standards, security guidance or the interpretation framework used to keep this guide bounded. Product-specific implementation still requires review in the actual codebase.