L6 · IDENTITY FUNDAMENTALS
Anatomy of your session
Inspect your session cookie, then end a session from another browser.
Planned
Steps
Find the session cookie in your browser's developer tools and note its attributes.
What the server will check: Nothing to check. Look for HttpOnly, Secure and SameSite, and read what each one prevents.
Sign in from a second browser.
What the server will check: Two active sessions for your account.
From the first browser, end the second browser's session.
What the server will check: You ended one of your own sessions after starting.
Ending a session on the server works even when the other browser still holds its cookie.
When it opens
This lab is planned. It opens when these are in place:
- Session list and sign-out controls on the Security page
The server checks your own account records and sign-in history, and shows only whether each step is done. It never shows the events themselves.