Keeping people signed in.
WHAT A SESSION IS
Data associated with a visitor across requests, identified by a cookie.
WHAT TO CONFIGURE
Cookies marked secure, so they travel only over encrypted connections Cookies inaccessible to scripts Restriction on cross-site sending A sensible expiry
WHAT TO DO ON SIGN-IN
Regenerate the session identifier.
WHY
It prevents an attacker who supplied an identifier beforehand from using it.
WHAT TO DO ON SIGN-OUT
Destroy the session entirely, not only clear its contents.
WHAT TO DO ON PASSWORD CHANGE
Invalidate other sessions.
WHAT NOT TO STORE IN A SESSION
More than is needed Anything sensitive that could be held elsewhere
WHAT TO CONSIDER
Where sessions are stored, and whether that scales.
WHAT TO SET
An idle timeout, appropriate to the sensitivity of the application.
WHAT TO PROVIDE
A way for a person to see and end their other sessions, in a sensitive application.
WHAT TO TEST
That signing out genuinely prevents further access.