Unlock an active session lock and dispose of it.
It cannot be reused. You should generally call this method only after verifying a user's identity.