Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8389321
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 9, 20262026-06-09T18:41:44+00:00 2026-06-09T18:41:44+00:00

I am not sure if I should post this on it security or /

  • 0

I am not sure if I should post this on it security or / stackoverflow because I am concerned about security and performance.

I am trying to find a reliable source for cookie management. I read though OWASP so i roughly know what can be dangerous.

But I need to authenticate my users with cookies. Is there a complete step by step guide?

What I did:

  • generate a random and unique string.

  • associate the random string with a user in my cache rndstring -> user

  • create a secure and signed cookie. value= hash(rndstring+secret)|rndstring

  • if the user comes back, I check if the hashes matches, and if the rndstring is in my cache.

  • if yes get the user.

I think my approach is flawed because I made it by myself.

Another problem would be that I safe the user object from the db in my cache. If the user updates his profile I would also have to update the cache.

I am using java with the play2 framework + mongoDB.

What resources can you recommend me?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-09T18:41:46+00:00Added an answer on June 9, 2026 at 6:41 pm

    I think this is a question for Security StackExchange and I note that you’ve asked similar questions there, recently with an excellent answer from DW. There are plenty of folk on the security.stackexchange.com forum who’ll critique your methodology.

    I personally wouldn’t recommend developing your own session management, in fact I’d advise against it. The “play framework” session management has been reviewed by many folks, whereas yours hasn’t and can easily have vulnerabilities that you’ve simply missed. I would use the built-in session management provided by your chosen programming framework. Have you read the play documentation?

    In terms of resources, you should check out the Secure Development Principles from David Rook – here and here.

    If you change your mind using cookies, you could look at web keys,, which is a method for inserting an unguessable token into a URL.

    When reading Owasp, did you read the latest Session Management cheatsheet? I think that a lot of your questions are answered there.

    One final resource is the SANS Top 25 Software Errors.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Preface : I'm honestly not sure if this should be on StackOverflow, SuperUser or
Just a sidenote : I'm not sure whether I should post this to serverfault
I found a similar post about this but still not sure. As I am
I'm not 100% sure how I should word this question but I'll try my
I'm not even sure how I should phrase this question. I'm passing some CustomStruct
Note: Not sure if this is the right stack, please tell if I should
I'm not sure if this is the right place to post this, but the
I am not sure what I should be doing here. Should I be hardcoding
I'm still a novice and I'm not sure how I should setup the profile
Many GDI+ classes implement IDisposable, but I'm not sure when I should call Dispose.

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.