Learning path

Full curriculum

Full curriculum

Unit content

Web sessions and secure cookies

After a user authenticates, a web application often needs to carry that identity across many HTTP requests.

A common server-side design creates a session and gives the browser a random, unguessable session identifier. The server maps that identifier to session state such as the authenticated principal.

The session identifier is a bearer credential: possession can be enough to act as the session's user. It should therefore be protected in transit and from unnecessary script access.

Browser cookies used for session identifiers commonly use

  • HttpOnly when client-side JavaScript does not need to read the credential;
  • Secure so the browser sends it only over HTTPS;
  • an appropriate SameSite policy controlling cross-site cookie sending.

A session identifier should be replaced when a security-sensitive identity transition makes reuse dangerous, such as authenticating an anonymous session. This limits session fixation, where an attacker tries to make the victim use a credential the attacker already knows.

Sessions also need expiry and server-side revocation so logout, compromise or policy changes can invalidate credentials before they would otherwise remain usable.