Immaniġġment ta' sessjonijiet jittratta l-ħefz tal-utenti loggati f'riċwiesti — u li tgħaddi b'mod sigur hija importanti, billi vulnerabilità tas-sessjonijiet (hijacking, fixation) jippermettu lill-attakkaturi li jimposonaw utenti. Sessjonijiet siguri jinvolvu handling korrett ta' tokens, sigurtà tal-cookies, u immaniġġment tal-ċiklu ta' ħajja.
Kif jaħdmu s-sessjonijiet
After login, the server keeps a SESSION identifying the user across requests:
→ a SESSION ID (or token) is stored client-side (usually a cookie) and sent each request
→ the server uses it to know who the user is (without re-authenticating each time)
→ the session ID/token is effectively a key to the user's account → must be PROTECTED.
