⚙️ Backend Engineering · Auth & Security Basics
Harden session authentication
Cookies, rotation, and revocation done right for server-rendered apps.
intermediate~35 minBackend EngineersAPI DevelopersPlatform Engineers
Steps
- 1Store session ID in HttpOnly, Secure, SameSite=Lax cookies
- 2Rotate session IDs on login and privilege change
- 3Keep server-side session records enabling instant revocation
- 4Expire idle sessions; re-authenticate before sensitive actions
- 5Rate-limit login and reset endpoints per IP and per account
- 6Log auth events to an append-only trail with device metadata
Common Pitfalls
- ▲JWTs in localStorage inviting XSS token theft
- ▲No server-side revocation after 'logout everywhere' requests
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill auth-security-session-auth-hardeningInstall globally
$ npx skills add aniruddhaadak80/skills --skill auth-security-session-auth-hardening -gTags
#auth#sessions#cookies#backend-engineering#auth-security