Skip to main content

Session

In Turkish
Oturum
Updated 3 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/session

In short

A session is a way for a server to remember a user across many requests, usually by keeping their data on the server and giving the browser a session ID.

What is a session in web development?

HTTP is stateless, which means each request stands on its own and the server does not automatically remember earlier ones. A session adds that memory: it is a period of interaction between one user and an application, typically from logging in to logging out, during which the server keeps track of who the user is and data such as the contents of their shopping cart.

In the classic server-side approach, when a user logs in the server creates a session record with their user ID and other data, stores it in memory, a database, or a cache such as Redis, and sends the browser a long random session ID in a cookie. The browser automatically includes that cookie with every later request, and the server uses the ID to look up the session. Logging out, or staying inactive past a timeout, deletes the session.

It works like a coat check: you hand over your coat and get a numbered ticket, and the ticket is only useful together with the counter that holds the coat. Because anyone who steals a session ID can impersonate the user, the cookie that carries it should be marked HttpOnly, Secure, and SameSite, and a new ID should be issued after login to prevent session fixation attacks.

Sessions are often confused with cookies and with token-based authentication. A cookie is just the transport that carries the session ID, while the session data itself lives on the server. With stateless tokens such as JWTs, the user's information travels inside a signed token, so the server doesn't need to look anything up, but the token is much harder to revoke before it expires.

Key takeaways

  • Sessions let a server remember a user across stateless HTTP requests.
  • The server stores session data and gives the client a random session ID.
  • The session ID usually travels in an HttpOnly, Secure cookie.
  • A session ends when the user logs out or after an inactivity timeout.
  • Server-side sessions are easy to revoke; stateless tokens like JWTs are not.

Example

Server-side sessions in Express.jsjavascript
// Using the express-session package
app.use(session({
  secret: process.env.SESSION_SECRET, // signs the session ID cookie
  resave: false, saveUninitialized: false,
  cookie: { httpOnly: true, secure: true, sameSite: "lax", maxAge: 30 * 60 * 1000 },
}));

app.post("/login", async (req, res) => {
  const user = await checkCredentials(req.body);
  if (!user) return res.sendStatus(401);
  req.session.userId = user.id; // stored on the server, not in the cookie
  res.send("Logged in");
});

app.get("/me", (req, res) => res.json({ userId: req.session.userId }));

Readers ask

What is the difference between a session and a cookie?

A cookie is a small piece of data stored in the browser and sent with requests, while a session is data stored on the server about a user's visit. In most setups the cookie only holds the session ID, which the server uses to find the session.

Should I use sessions or JWTs for authentication?

Server-side sessions are simple and can be revoked instantly by deleting them, which suits most traditional web apps. JWTs avoid a lookup on every request and can suit APIs shared by many services, but they are harder to revoke before they expire.

How long should a session last?

It depends on the risk. Banking apps often end sessions after a few minutes of inactivity, while low-risk apps may keep users signed in for weeks; a common pattern combines a short idle timeout with an absolute maximum lifetime.

Often compared

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings