Skip to main content

Secure a browser session through an identity-aware proxy

Separate identity-provider, proxy, and application sessions while controlling cookies, CSRF, logout, renewal, and origin trust.

Learning outcomes

  • Trace identity-provider, proxy, and application session state separately.
  • Set cookie, origin, CSRF, lifetime, renewal, and reauthentication controls by session owner.
  • Explain what local, provider, and application logout each terminate.
  • Test fixation, theft, replay, stale authorization, and cross-origin failure paths.

System and boundaries

Model at least three state owners. The identity provider maintains its sign-in session. The identity-aware proxy maintains a session for access to its routes. The application can maintain a separate local session or use verified identity on each request. These cookies and logout events are not interchangeable.

Include the browser origin, callback routes, proxy, identity provider, upstream application, session stores, policy service, and evidence. Name which component creates, encrypts or signs, validates, rotates, and revokes each cookie or token.

Request and decision flow

Trace first sign-in, callback correlation, proxy session creation, route authorization, upstream identity delivery, application session creation, state-changing request, renewal, step-up, and logout. Bind callback state to the initiating browser. Set cookies with secure transport, appropriate HttpOnly and SameSite behavior, narrow Domain and Path, and explicit idle and absolute limits.

Protect state-changing application requests against cross-site request forgery. Reauthorize sensitive actions from current application state. Define which logout terminates provider, proxy, application, and downstream sessions.

Failure domains

  • An attacker fixes or steals a proxy or application session.
  • A broad cookie domain sends session state to an unintended host.
  • A cross-site request performs a state-changing action.
  • Proxy logout leaves the application session active.
  • Provider disablement does not reach an existing proxy connection.
  • Silent renewal extends access beyond the intended absolute limit.
  • A valid route session is treated as object authorization.

Design tradeoffs and residual risk

Short sessions and frequent reauthentication reduce stale access but add user friction and identity-provider dependency. SameSite restrictions reduce cross-site attacks but can break valid federation flows if applied without flow analysis. Stateless sessions simplify storage but make immediate revocation harder. Multiple session owners improve separation but complicate logout and evidence.

Measure end-to-end termination instead of assuming that one logout removed all authority.

Pomerium boundary

Pomerium owns its browser session and route policy. The identity provider owns its authentication session. An upstream owns any local session and all object and action authorization. Pomerium logout cannot guarantee that an independent upstream session ended unless the integration explicitly coordinates it.

Exercise

Draw all cookies, tokens, stores, callbacks, and logout calls for one web application. Record issuer, audience, scope, lifetime, renewal, revocation, Domain, Path, SameSite, Secure, and HttpOnly behavior.

Test stolen and fixed cookies, cross-site POST, provider disablement, group removal, route logout, application logout, absolute expiry, and an already open connection.

Evaluation checklist

  • Are identity-provider, proxy, and application sessions separate in the model?
  • Are cookie scope, origin validation, CSRF, renewal, and expiry explicit?
  • Does sensitive application authorization use current resource state?
  • Can the team state what each logout and disable event actually terminates?
  • Is end-to-end revocation latency measured for sessions and connections?

Next learning unit

Revocation Latency

Measure how long a disabled identity, authenticator, session, claim, or permission can continue to authorize action.

Sources and further reading

Keep learning

Identity and AuthenticationSecurity Operations and Risk

Revocation Latency

Measure how long a disabled identity, authenticator, session, claim, or permission can continue to authorize action.

Learn this term
Application and Service AccessStandards and Protocols

Secure Route Selection

Select a route from trusted authority and path data so an attacker cannot redirect policy or credentials to the wrong upstream.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo