Demo article for reviewing the website layout.
Know the session lifecycle
A session starts after authentication and ends at logout or expiry. Understand where the session identifier is stored and how the server validates it.
Protect the identifier
Use HTTPS and appropriate cookie attributes. Review expiry, rotation after authentication and invalidation after sign-out. Keep identifiers out of URLs and logs.
Test only your own lab
Create a local practice application with two test accounts. Check that one account cannot read the other account’s data. Document expected behavior before testing.



