December 2015
Intermediate to advanced
232 pages
5h 8m
English
In this chapter we looked at the session, an integral part of the authentication scheme. We started by setting up a session system and then added layers of security. We looked at how to add a Time-to-Live, secure cookies, mitigate session-fixation attacks, and add protections against hijacking.
We’ve covered our bases for authenticating a user and setting up a secure session, so in the next chapter we’ll look at how to allow or deny user access to resources based on the user’s access level.
Read now
Unlock full access