Glossary

The words, without the shrug

Every term the courses use, defined in one line and then in a paragraph. Written to be read out of order.

Clear

Showing 4 of 4 matching “Cookie”

HttpOnly

Backend

A cookie flag that hides it from JavaScript.

Marks a cookie unreadable by page scripts, so a single injected script cannot steal a session. Tokens stored in local storage have no equivalent protection.

See also Cookie, Session

Session

Backend

The server-side record that you are logged in.

A stored record the server looks up on each request using an id from a cookie. Slower than a signed token because of the lookup, but logging out is instant and reliable.

See also Cookie, JWT, Authentication

Stateless

Backend

Each request starts from nothing.

The server remembers nothing about you between requests by default. Memory has to be added deliberately, which is exactly what cookies and sessions are for.

See also HTTP, Session, Serverless