Unit content
Web sessions and secure cookies
After a user authenticates, a web application often needs to carry that identity across many HTTP requests.
A common server-side design creates a session and gives the browser a random, unguessable session identifier. The server maps that identifier to session state such as the authenticated principal.
The session identifier is a bearer credential: possession can be enough to act as the session's user. It should therefore be protected in transit and from unnecessary script access.
Browser cookies used for session identifiers commonly use
HttpOnlywhen client-side JavaScript does not need to read the credential;Secureso the browser sends it only over HTTPS;- an appropriate
SameSitepolicy controlling cross-site cookie sending.
A session identifier should be replaced when a security-sensitive identity transition makes reuse dangerous, such as authenticating an anonymous session. This limits session fixation, where an attacker tries to make the victim use a credential the attacker already knows.
Sessions also need expiry and server-side revocation so logout, compromise or policy changes can invalidate credentials before they would otherwise remain usable.