Sessions vs tokens

P54.sessions-tokens.01 · Audience: guest, it-ml, language-pro · Prerequisites: Passwords done right

Real LLM grading for this pageLLM grading (this page):

Once a user is authenticated, something has to carry that session on every subsequent request — usually a cookie. Its flags decide whether a cross-site-scripting (XSS) bug — injected script running in the victim's page — or a cross-site request can hijack the session. This module hardens a session cookie against exactly those attacks, using the platform's own httpOnly cookie session (ADR-007 D8) as the worked example.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — harden a session cookie

Loading exercise…

My notes on this module

Loading your notes...

Sessions vs tokens — TransformerLab