Lesson 11 / الدرس 11

Cookies and sessions / ملفات cookie والجلسات

HTTP forgets you between every request. Everything that feels like being remembered — staying logged in, a basket that survives a page change — is built on one small header sent back each time.

ينساك HTTP بين كل طلب وآخر. وكل ما يشبه أن تُتذكَّر — بقاؤك مسجَّل الدخول، وسلة تنجو من تغيير الصفحة — مبني على ترويسة صغيرة واحدة تُعاد في كل مرة.

HTTP is stateless: each request is a complete question with no memory of the one before it. The server that just sent you a page has, as far as the protocol is concerned, never heard of you. That is a deliberate design — it is what lets any of a hundred machines answer your next request — and it leaves one obvious problem.

If nothing is remembered, how does a site know you logged in one request ago? The answer is that the server hands you a note and you hand it back with every later request. That note is a cookie: a small named value the browser stores per site and attaches to each request to that site automatically.

The exchange, in two headers

Response, once, when you log in:
  Set-Cookie: session=7f3a91c0; HttpOnly; Secure; SameSite=Lax; Max-Age=1209600

Every request afterwards, automatically:
  Cookie: session=7f3a91c0
Two headers you already met in lesson 9, doing their real job. Note what the value is: not your name and not your password, but a long random string that means nothing on its own.

That randomness is the whole trick, and it is what the word session means. The server keeps the real information — who you are, what is in your basket — on its own side, filed under that random string. The browser only ever carries the ticket number. Steal the ticket and you are that user; but read it and you learn nothing.

The words after the value

AttributeWhat it doesWhy it matters
HttpOnlyHides the cookie from page scriptsA script bug cannot steal the session
SecureOnly ever sent over HTTPSIt never travels in readable form
SameSite=LaxNot sent on requests from other sitesBlocks the attack in lesson 14
Max-Age / ExpiresHow long to keep itWithout one it dies when the browser closes
Domain / PathWhich addresses it is sent toKeeps one site out of another

These are not decoration. A session cookie without HttpOnly, Secure and SameSite is the single most common serious mistake in web applications.

<p class="ok">session=7f3a91c0 — a ticket number</p>
<p class="bad">role=admin — a suggestion from a stranger</p>
Run it, then write the version you would explain to a colleague. Being able to say quickly why one of these is safe and the other is not is worth more than memorising the attribute list.

Try it live / جرّب بنفسك

Preview / المعاينة

Check yourself / اختبر نفسك

1. Why is a session cookie a random string rather than a username?

2. A site stores role=admin in a cookie and trusts it. What is wrong?

3. What does HttpOnly protect against?

Your task / مهمتك

Explain the login exchange on a page, as if to someone who has just asked "but how does it know it is still me?". Show the two headers, say what the value is and is not, and list the attributes with what each one prevents. Finish with one example of a value that must never be a cookie, and why.

اشرح تبادل الدخول في صفحة، كما لو أن أحدهم سألك للتو: "لكن كيف يعرف أنني ما زلت أنا؟". أظهر الترويستين، وقل ما القيمة وما ليست، وعدّد السمات مع ما تمنعه كل واحدة. واختم بمثال على قيمة لا يصح أن تكون cookie أبدًا، ولماذا.

  • Both headers appear, in the right order الترويستان موجودتان بالترتيب الصحيح
  • It is clear that the real data stays on the server واضح أن البيانات الحقيقية تبقى عند الخادم
  • At least three attributes, each with what it prevents ثلاث سمات على الأقل، لكل واحدة ما تمنعه
  • An example of a value that must not be a cookie مثال على قيمة لا يصح أن تكون cookie
How do you want to submit? / كيف تريد التسليم؟