Frontend Session Service
Exchanges A+ tokens for opaque browser sessions and resolves those sessions on later requests.
Persistent session state contains only a digest of the session ID and an authenticated encryption of the A+ token. Resolution enforces idle and absolute expiry, revokes invalid upstream tokens, and limits last-use writes to the configured interval.