Problem Statement
Which practice best reduces risk in web session management?
Explanation
Strong session management means random identifiers, secure and httpOnly cookies, and enforced expiry. Idle timeouts log out inactive users. Absolute timeouts end long-lived sessions even if active. These steps limit theft, fixation, and replay.
Code Solution
SolutionRead Only
Set-Cookie: sid=abc...; Secure; HttpOnly; SameSite=Strict; Max-Age=1800
