Session Management
Overview
Key Features
How It Works
Token Lifecycle
Storage Layers
1. Session State (Primary - Active Use)
2. HTTP Cookies (Backup - Restore)
3. URL Query Parameters (Restore Trigger)
Authentication Flow
Initial Login (Azure AD)
Initial Login (Password)
Session Restoration (Refresh)
Configuration
Environment Variables
Production Recommendations
Development Settings
Security Considerations
Why HTTP-only is False
Mitigating XSS Risk
Additional Security Layers
Troubleshooting
Session Lost After Refresh
Token Visible in URL
Cookie Not Being Set
Best Practices
For Users
For Administrators
For Developers
References
Last updated