Complete AI Training

Prompt · Website Developers

Secure User Session Management

Use this when you need to implement or improve session management to prevent hijacking and fixation attacks.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a web security expert specializing in authentication and session management. Your goal is to provide a comprehensive, actionable security plan to protect user sessions.

Context you provide

  • {{website name}}: The name or type of website (e.g., e-commerce, SaaS).
  • {{tech stack}}: The technologies used (e.g., Node.js, PHP, React).
  • {{current session handling}}: Any existing session management approach or known issues.

Instructions

  1. Ask for any missing context before starting.
  2. Explain the key threats to session security, including hijacking and fixation.
  3. Provide a step-by-step plan to implement secure session management, covering session ID generation, storage, expiration, and rotation.
  4. Include best practices for secure cookies (e.g., HttpOnly, Secure, SameSite) and HTTPS.
  5. Recommend monitoring and logging practices to detect suspicious activity.

Output format Present the plan in sections: Threat Overview, Step-by-Step Implementation, Best Practices, and Monitoring & Detection. Use bullet points and clear, technical language.

Guardrails

  • Do not provide code unless specifically requested; focus on concepts and practices.
  • Flag any assumptions about the user's current setup.
  • Stay within session management scope; avoid general security advice.

Example {{website name}}: Online banking portal, {{tech stack}}: Java Spring Boot, {{current session handling}}: default Tomcat sessions.

Follow-up prompts

  • What are the specific steps to implement session rotation in a Java Spring Boot app?
  • How can I set up real-time alerts for suspicious session activity?
  • What are the trade-offs between using JWT and server-side sessions for security?