Learning Hub
← Web Development

Authentication and sessions

6 min readΒ·Updated 2026-09-09

Authentication proves who a user is; a session remembers that proof across requests. A secure session uses an unpredictable identifier, server-side expiry, protected cookies, and explicit logout or revocation.

Authentication proves who a user is; a session remembers that proof across requests. A secure session uses an unpredictable identifier, server-side expiry, protected cookies, and explicit logout or revocation.

At a glance

Question Practical answer
When is it useful? After login, a server stores session state and sends an HttpOnly, Secure, SameSite cookie; later requests present the cookie without exposing the password again.
What should you do? Sketch login, authenticated request, expiry, logout, and stolen-cookie scenarios for a tiny notes app.
How do you know it worked? Expired or revoked sessions cannot access protected routes, cookies are unavailable to client JavaScript, and password changes invalidate sensitive sessions.
Common failure Do not store raw passwords or long-lived session secrets in localStorage; hashing passwords and protecting sessions solve different problems.
flowchart LR
  A[Question] --> B[Authentication and sessions]
  B --> C[Small example]
  C --> D[Evidence]

The important idea is not to stop at a definition: connect the concept to a small example and observable evidence.

Worked example

After login, a server stores session state and sends an HttpOnly, Secure, SameSite cookie; later requests present the cookie without exposing the password again.

Before acting, write the success signal. Change one condition at a time, observe the result, and record assumptions. For Authentication and sessions, this separates what you know from what you are merely guessing.

Practice in 20–30 minutes

Goal: Sketch login, authenticated request, expiry, logout, and stolen-cookie scenarios for a tiny notes app.

  1. Record the starting state and your prediction.
  2. Implement the smallest version without adding unnecessary tools.
  3. Change exactly one input or constraint and repeat.
  4. Save a command, screenshot, output, or checklist as evidence.

Expected result: Expired or revoked sessions cannot access protected routes, cookies are unavailable to client JavaScript, and password changes invalidate sensitive sessions.

What can go wrong

Do not store raw passwords or long-lived session secrets in localStorage; hashing passwords and protecting sessions solve different problems.

When the result differs from your prediction, do not change many things at once. Check inputs, versions, environment, permissions, and logs, then repeat from the smallest example.

Definition of done

  • I can explain the concept in my own words.
  • I completed the small example and kept evidence.
  • I know one failure mode and how to check it.
  • Someone else can repeat the work without guessing missing steps.

Go deeper

Use the linked resource or repository at the end of the page when you need a full implementation. Check current versions before applying commands to a real project.