# Consumer contract
`SessionScope` is a cloneable, in-memory identity boundary for Web-code service handles. `SessionScope::new` creates a distinct boundary; cloning preserves its identity.
`recover(user, source)` and `refresh(user, source)` retain the supplied exact `Arc<SourcePackage>` and recover a `CodeDocument` only with `CodeDocument::from_source_package`. `OpenedLibrary::document` exposes that recovered document. `validate` accepts a handle only when its scope and 12-byte user match and its retained source equals the current `SourcePackage` byte-for-byte.
`replacement` first validates the handle, then replaces exactly one complete `String` slot selected by `DocumentPart::{Documentation, Code}`. It preserves the other authored bytes and identity, and builds the result through `CodeDocument::new` and `CodeDocument::to_source_package`.
`mint_evidence` creates `CheckEvidence` only from a valid opened/current source. `evidence_matches` first validates the opened/current source and then reports whether evidence has the same scope, user, and exact source bytes. Evidence therefore stops matching after a successful replacement is refreshed.
`OpenedLibrary` and `CheckEvidence` are cloneable and opaque. They expose no source identity, authentication, storage, cache, locking, checking, publication, protocol, or retry behavior. All operations are pure apart from reference-count updates and allocation. Work is linear in the relevant package, documentation, or code bytes.
`SessionError::ForeignHandle` covers a foreign scope or user, `SessionError::StaleSource` covers changed current source bytes, and `SessionError::InvalidDocument` retains the exact `DocumentError` display text. `SessionError` implements the standard error traits.