Bulletproof sessions – secure, cookieless session handling
Bulletproof sessions – secure, cookieless session handling
I had this idea for a few years already and now I also managed to implement a proof of concept for it: instead of relying on cookies or tokens to identify a user, have a service worker intercept and sign all the requests to the server (with a private key generated when the service worker is initially installed). The server identifies the user based on the public key corresponding to the signature. BAM! no more cookie sessions, so no more sessions hijacking and session replay attacks. I also wrote a blog post [0] detailing some advantages over the traditional session handling mechanisms, but I feel this enables endless possibilities. Appreciate your thoughts&feedback! [0] https://programming.tudorconstantin.com/2025/03/bulletproof-...
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
iron-session, stateless web sessions
Track your sauna sessions and get insights.
Podman container with VNC GNOME Phosh session
Bash-sessions, a session manager for the bash shell
Inter-session messaging between Claude Code sessions
tmux-session-spectrum – different colors for different sessions in tmux
Annotated Live TLS 1.3 Session
tmuxp – session manager for tmux
PPPoE client with session handoff between redundant FreeBSD routers
Manymux: A Terminal Session Multiplexer