In every case, authentication was treated as a one-time gate rather than a continuous guarantee. The system checked identity once — at login — and assumed the result would stay valid forever, under all conditions, for all operations.
Secure authentication isn't a gate. It's a continuous contract that must be enforced at every layer.