Introduction
Sessions maintain user state across requests. Misconfigured sessions enable session hijacking, fixation attacks, and unauthorized access.
Key Concepts
Session Hijacking: Stealing a session ID to impersonate a user.
Session Fixation: Tricking a user into using a session ID chosen by the attacker.
Session Cookie Attributes: Secure, HttpOnly, SameSite flags that protect cookies.
Real World Context
Session hijacking was used in the Firesheep attack, which let anyone on a Wi-Fi network steal Facebook and Twitter sessions in real time. Without Secure and HttpOnly flags on session cookies, any network eavesdropper or XSS vulnerability can compromise user sessions.
Deep Dive
Secure Session Configuration
python# settings.py SESSION_ENGINE = 'django.contrib.sessions.backends.db' SESSION_COOKIE_SECURE = True # HTTPS only SESSION_COOKIE_HTTPONLY = True # No JS access SESSION_COOKIE_SAMESITE = 'Lax' # CSRF protection SESSION_COOKIE_AGE = 86400 # 24 hours SESSION_EXPIRE_AT_BROWSER_CLOSE = False SESSION_SAVE_EVERY_REQUEST = True # Refresh expiry on activity
Preventing Session Fixation
pythonfrom django.contrib.auth import login def login_view(request): user = authenticate(request, ...) if user: login(request, user) # Rotate session ID after login request.session.cycle_key()
Session Storage Options
python# Database (default) - most secure SESSION_ENGINE = 'django.contrib.sessions.backends.db' # Cache (Redis) - fast, requires secure cache SESSION_ENGINE = 'django.contrib.sessions.backends.cache' SESSION_CACHE_ALIAS = 'default' # Signed cookies - no server storage needed SESSION_ENGINE = 'django.contrib.sessions.backends.signed_cookies'
Common Pitfalls
- Not rotating session IDs on login — Without cycle_key(), an attacker who obtained a session ID before login can use it after the user authenticates (session fixation).
- Using signed cookie sessions for sensitive data — Signed cookie sessions are tamper-proof but not encrypted; users can decode and read the session contents.
Best Practices
- Rotate on login: Call cycle_key() after successful authentication.
- Use HTTPS: Set SESSION_COOKIE_SECURE=True.
- Set HttpOnly: Prevent JavaScript access to session cookie.
- Short lifetimes: Balance security vs user convenience.
Summary
Secure sessions require HTTPS, HttpOnly cookies, session rotation on login, and appropriate storage backends. Always rotate the session ID after authentication state changes.