Drop the session (logout).
Resolve the principal for a request:
Establish the session for a verified user (eg. set a cookie) on the auth-success response.