Cookie
BackendA small value the browser attaches to every request.
How a stateless protocol manages to remember you. The browser stores it and sends it automatically with each request to that site. Marking one HttpOnly prevents JavaScript from reading it, which stops an injected script stealing a session.
See also Session, HttpOnly, JWT
HTTP
FrontendThe request-and-response protocol of the web.
The rules by which a client asks and a server answers. A request is a method, a path, headers, and maybe a body; a response swaps the method for a status code. Stateless by default.
See also Status code, Stateless, Endpoint
HttpOnly
BackendA cookie flag that hides it from JavaScript.
Marks a cookie unreadable by page scripts, so a single injected script cannot steal a session. Tokens stored in local storage have no equivalent protection.
See also Cookie, Session
REST
BackendAn API style organised around things.
Endpoints named after resources (/users, /orders) with HTTP verbs saying what to do to them. Highly cacheable and easy to inspect. A rich screen may need several calls.
See also GraphQL, RPC, Endpoint
TLS
FrontendThe encryption behind the S in HTTPS.
Makes the connection private and tamper-proof. Without it, anything between the user and your server can read and modify the page. Costs an extra handshake on the first connection.
See also DNS, Latency