Cookie Sessions
Cookie/session auth is another common authentication strategy.
Instead of sending a JWT in an Authorization header, the browser sends a cookie automatically.
Basic session idea
- User logs in.
- Server creates a session id.
- Server stores session data.
- Server sends session id in a cookie.
- Browser sends cookie on future requests.
- Server uses session id to find the user session.
Cookie settings
Important cookie options:
httpOnly: JavaScript cannot read the cookie.secure: send only over HTTPS.sameSite: controls cross-site sending.maxAge: expiration time.
Example:
res.cookie('sessionId', sessionId, {
httpOnly: true,
secure: true,
sameSite: 'lax',
})
JWT vs sessions
| Strategy | Where auth state lives |
|---|---|
| JWT | Usually in token claims |
| Session | Server-side session store |
Sessions make invalidation easier because the server can delete the session.
JWT can be more stateless, but invalidation needs extra design.
Common mistake
Do not store sensitive auth cookies without httpOnly in real apps.
If JavaScript can read the cookie, XSS risk becomes worse.
Interview answer
Cookie-session authentication stores a session id in a browser cookie and keeps session data on the server or a session store. The browser sends the cookie automatically. Secure session cookies should use options like httpOnly, secure, and sameSite.