Sessions and Tokens — From the Browser to the Mesh
What flows after login, and where it breaks.
고급 · Lessons 27 · Lab 9
Start the lab
Curriculum
Session cookie attributes and prefixes
Server sessions and session fixation
CSRF and the limits of SameSite
Keeping tokens out of the browser with a BFF
JWT signature verification and alg confusion
Refresh token rotation and reuse detection
Token revocation strategies
Service-to-service delegation and token exchange
JWT and mTLS at the mesh boundary
Reference docs