⚡AgentSkills
⚙️ Backend Engineering · Auth & Security Basics

Harden session authentication

Cookies, rotation, and revocation done right for server-rendered apps.

intermediate~35 minBackend EngineersAPI DevelopersPlatform Engineers

Steps

  1. 1Store session ID in HttpOnly, Secure, SameSite=Lax cookies
  2. 2Rotate session IDs on login and privilege change
  3. 3Keep server-side session records enabling instant revocation
  4. 4Expire idle sessions; re-authenticate before sensitive actions
  5. 5Rate-limit login and reset endpoints per IP and per account
  6. 6Log auth events to an append-only trail with device metadata

Common Pitfalls

  • ▲JWTs in localStorage inviting XSS token theft
  • ▲No server-side revocation after 'logout everywhere' requests

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill auth-security-session-auth-hardening
Install globally
$ npx skills add aniruddhaadak80/skills --skill auth-security-session-auth-hardening -g

Tags

#auth#sessions#cookies#backend-engineering#auth-security

Related skills

Parse, don't validate: coerce untrusted input into typed values once at the edge.

⚙️ Backend Engineering·~25m