Usimamizi wa mgogoro unashughulikia kuweka watumiaji wakiwa na jina zuri kwenye maombi yote — na kuifanya kwa usalama ni muhimu, kwa kuwa mgogoro haujaditishwa (ubinafsi, kuanzishwa) kuruhusu waaidha kuigeuza watumiaji. Vikali vya mgogoro salama vinajumuisha kumuamua vizuri njia, salama ya kuki, na usimamizi wa mzunguko.
Jinsi mgogoro unavyofanya kazi
After login, the server keeps a SESSION identifying the user across requests:
→ a SESSION ID (or token) is stored client-side (usually a cookie) and sent each request
→ the server uses it to know who the user is (without re-authenticating each time)
→ the session ID/token is effectively a key to the user's account → must be PROTECTED.
