TT Lab
Get started
Learn Learning paths Courses

Sessions and Tokens — From the Browser to the Mesh

What flows after login, and where it breaks.

고급 · Lessons 27 · Lab 9

Start the lab

Curriculum

Session cookie attributes and prefixes

Server sessions and session fixation

CSRF and the limits of SameSite

Keeping tokens out of the browser with a BFF

JWT signature verification and alg confusion

Refresh token rotation and reuse detection

Token revocation strategies

Service-to-service delegation and token exchange

JWT and mTLS at the mesh boundary

Reference docs