AntiPattern

Session Credential Misbinding

session-credential-misbinding

Session state gets bound to the wrong transport or lifecycle—cookies not sent, SSR runs before session hydration, or logout/session-end events never fire—so requests and user credentials cannot be correlated reliably across server and client.