BackendFrontendSecurityTable-stakes
Cookies & Sessions
Also written as Cookie, Session Management, Session Cookie
How a website remembers you between page loads. The server keeps a 'session' about you, and your browser holds a cookie that identifies it. It is the traditional alternative to token-based login like JWT.
Think of it like
A cloakroom ticket: the coat stays with the venue, and the ticket proves which one is yours.
Junior or senior?
Basic, but the security details separate levels.
Senior sounds like
Mentions HttpOnly and Secure flags, SameSite, and session expiry.
Ask them
“How did you protect session cookies from being stolen or misused?”