Labs / Session BFF · refresh leak
Session BFF · refresh leak
Refresh is HttpOnly, but /auth/session may still return it in JSON. Curl the session, patch the BFF, prove XSS cannot recover refresh.
Terminal
How to work it
Same loop as a small repo checkout: read README, run the test, inspect the failure, change the code, re-run until it exits 0.
This is a simulated POSIX-ish shell (not a full VM). No production network.
New here? help lists tools. Stuck? help next gives one hint at a time.
Related note: /proof/notes/session-bff-refresh-leak/ · All labs
Engineering commentary only — not audit, legal, or certification advice. Simulated tokens only.