When a session is terminated, X clients from that session can reconnect to a newly created session, provided the user gets the same display number. This can commonly occur when using "End exisiting session". One possible method is to give the xauthority file a unique name for each session.
We must take care not to leave too many stale Xauthority files behind.
Note that since bug 7788 the separation between a user's sessions is gone. In other words, unique Xauthority file paths would no longer resolve this issue.