> Also the page that initiated it should periodically refresh itself to see if the session was validated somewhere else.
I guess the link must be disabled / invalidated after first use and your auth server and client obviously must verify if a given link is still valid.