Login issues a short-lived access token (TTL ~45s) plus a refreshtoken. Rotating swaps both for a fresh pair โ the old refresh becomes invalid. Replaying that already-rotated refresh trips the server's reuse-detection control and revokes the session entirely.
The status is computed server-side. Assert on #session-state[data-state], never on client-only text.