Learning on Web Dev Open is free for all.

Backend Engineering > Who is asking, and what may they doSessions and tokens, on their merits
Phase 05Who is asking, and what may they do262 of 434

Sessions and tokens, on their merits

Implement a session cookie properly, then the token version, and be able to say which one your application should have.

Build55 minAI implements

Build this in your own editor

This one runs on your machine rather than in the browser workbench. Work to the outcomes below, then come back and mark it complete.

You should now be able to

  • Set a cookie with the right flags and understand each one
  • Implement login, logout and a protected route
  • State what happens when you need to revoke access immediately
Ask the community

Loading…