Lesson 11 / الدرس 11
Cookies and sessions / ملفات cookie والجلسات
HTTP forgets you between every request. Everything that feels like being remembered — staying logged in, a basket that survives a page change — is built on one small header sent back each time.
ينساك HTTP بين كل طلب وآخر. وكل ما يشبه أن تُتذكَّر — بقاؤك مسجَّل الدخول، وسلة تنجو من تغيير الصفحة — مبني على ترويسة صغيرة واحدة تُعاد في كل مرة.
HTTP is stateless: each request is a complete question with no memory of the one before it. The server that just sent you a page has, as far as the protocol is concerned, never heard of you. That is a deliberate design — it is what lets any of a hundred machines answer your next request — and it leaves one obvious problem.
If nothing is remembered, how does a site know you logged in one request ago? The answer is that the server hands you a note and you hand it back with every later request. That note is a cookie: a small named value the browser stores per site and attaches to each request to that site automatically.
The exchange, in two headers
Response, once, when you log in:
Set-Cookie: session=7f3a91c0; HttpOnly; Secure; SameSite=Lax; Max-Age=1209600
Every request afterwards, automatically:
Cookie: session=7f3a91c0
That randomness is the whole trick, and it is what the word session means. The server keeps the real information — who you are, what is in your basket — on its own side, filed under that random string. The browser only ever carries the ticket number. Steal the ticket and you are that user; but read it and you learn nothing.
The words after the value
| Attribute | What it does | Why it matters |
|---|---|---|
| HttpOnly | Hides the cookie from page scripts | A script bug cannot steal the session |
| Secure | Only ever sent over HTTPS | It never travels in readable form |
| SameSite=Lax | Not sent on requests from other sites | Blocks the attack in lesson 14 |
| Max-Age / Expires | How long to keep it | Without one it dies when the browser closes |
| Domain / Path | Which addresses it is sent to | Keeps one site out of another |
These are not decoration. A session cookie without HttpOnly, Secure and SameSite is the single most common serious mistake in web applications.
HttpOnly وSecure وSameSite هو أشيع خطأ خطير في تطبيقات الويب على الإطلاق.role=admin أو price=5 ليست حقيقة — بل اقتراح من غريب. خزّن المعرّف العشوائي، وأبقِ المعنى عند الخادم، وتحقق منه كل مرة.<p class="ok">session=7f3a91c0 — a ticket number</p>
<p class="bad">role=admin — a suggestion from a stranger</p>
localStorage يسع أكثر ويعيش أطول. والفرق المهم هنا أن cookie يُرسل تلقائيًا مع كل طلب وlocalStorage لا يُرسل، وهذا بالضبط سبب استخدام الجلسات لـcookies وسبب وجود هجوم الدرس 14 أصلًا.Try it live / جرّب بنفسك
Check yourself / اختبر نفسك
1. Why is a session cookie a random string rather than a username?
The cookie is a ticket number. Anyone who reads it learns nothing, and the server can invalidate the ticket without changing anything about the account.
2.
A site stores role=admin in a cookie and trusts it. What is wrong?
role=admin في cookie ويثق بها. ما الخطأ؟This is lesson 2's rule once more: data arriving from a client is a claim. Anything that decides permission belongs on the server.
3.
What does HttpOnly protect against?
HttpOnly؟It makes the cookie invisible to page scripts, so a script that should not be running still cannot steal the session. Secure is the one that handles encryption.
Secure.Score / النتيجة: 0 / 3
Your task / مهمتك
Explain the login exchange on a page, as if to someone who has just asked "but how does it know it is still me?". Show the two headers, say what the value is and is not, and list the attributes with what each one prevents. Finish with one example of a value that must never be a cookie, and why.
اشرح تبادل الدخول في صفحة، كما لو أن أحدهم سألك للتو: "لكن كيف يعرف أنني ما زلت أنا؟". أظهر الترويستين، وقل ما القيمة وما ليست، وعدّد السمات مع ما تمنعه كل واحدة. واختم بمثال على قيمة لا يصح أن تكون cookie أبدًا، ولماذا.
- Both headers appear, in the right order الترويستان موجودتان بالترتيب الصحيح
- It is clear that the real data stays on the server واضح أن البيانات الحقيقية تبقى عند الخادم
- At least three attributes, each with what it prevents ثلاث سمات على الأقل، لكل واحدة ما تمنعه
- An example of a value that must not be a cookie مثال على قيمة لا يصح أن تكون cookie