# Sessions and Tokens — OWASP Top 10

Source: https://www.skillbyai.com/en/owasp-top-10/u-session

> Cookies, JWTs and expiry.

## Protect the proof of login

After login, a session cookie or token proves identity, so it must be protected: generate session IDs with a secure random source, **regenerate** them at login (prevents session fixation), set cookies `Secure`, `HttpOnly` and `SameSite`, expire sessions after inactivity and on logout, and invalidate them on password change. With **JWTs**, verify the signature with an explicit algorithm allow-list (never accept `alg: none`), check `exp`, `aud` and `iss`, keep lifetimes short with refresh tokens, and avoid storing long-lived tokens in localStorage where XSS can read them.

## Verifying a JWT strictly

Python with the PyJWT library (a sketch).

```python
import jwt

claims = jwt.decode(
    token,
    key=PUBLIC_KEY,
    algorithms=["RS256"],              # explicit allow-list
    audience="https://api.example.com",
    issuer="https://login.example.com/",
    options={"require": ["exp", "iat", "sub"]},
)
user_id = claims["sub"]
```

## Log out must work server-side

Invalidate the server-side session or revoke the refresh token; deleting a cookie in the browser alone is not enough.

**Quiz:** Why regenerate the session ID at login?

- [ ] To make cookies smaller
- [x] To prevent session fixation, where an attacker sets a known session ID beforehand
- [ ] To improve caching
- [ ] To log the user out

*Answer:* To prevent session fixation, where an attacker sets a known session ID beforehand. New privilege level, new session.
