- Store user password hash in session during login
- Validate password hash compatibility on requests to prevent session reuse
- Revoke all user access tokens and clear session on ChangePassword
Bind OAuth state payloads to the initiating session token and user ID.
Verifies session token hash continuity during callback, and validates that
the user ID completing the binding flow matches the user ID that initiated it.