Cybersecurity › Web Application Security
Session Management
22 ControlsSession Management
Protect the session ID tokens after a user authenticates.
- Generate new session IDs upon login
- Set
SecureandHttpOnlyflags on cookies - Enforce absolute and idle session timeouts
- Invalidate sessions properly on the server upon logout