Ensure each TC Token issued corresponds to a unique session identifier that is both hard to guess and never reused. ## Tasks - [ ] Enforce uniqueness at the DB/session store level - [ ] Reject duplicate session_id reuse - [ ] Add test cases for collision resistance ## Reference - TR-03130 Part 1, §3.3.1