BackendFrontendSecurityTable-stakes

Cookies & Sessions

Also written as Cookie, Session Management, Session Cookie

How a website remembers you between page loads. The server keeps a 'session' about you, and your browser holds a cookie that identifies it. It is the traditional alternative to token-based login like JWT.

Think of it like

A cloakroom ticket: the coat stays with the venue, and the ticket proves which one is yours.

Junior or senior?

Basic, but the security details separate levels.

Senior sounds like

Mentions HttpOnly and Secure flags, SameSite, and session expiry.

Ask them

“How did you protect session cookies from being stolen or misused?”