- Session IDs are now rotated after successful SAML‑P or WS‑Fed login, issuing a new session cookie.
- Aligns SAML‑P/WS‑Fed session handling with OAuth2/OIDC behavior for consistent, secure management.
- Update any client‑side logic or integrations that rely on persisting the pre‑login session ID.