Skip to content

Latest commit

 

History

History
29 lines (15 loc) · 638 Bytes

webSecrity.md

File metadata and controls

29 lines (15 loc) · 638 Bytes

Web Secrity

Authentication 認證管理

  • Check user's identity, which is called Authentication
  • No matter user's identified or not, server will still give them session id

So, marketing can take the number of session ID to know how many people visit the sites.

  • Client's Cookie saves seesion id and cookie will be sent out when the session is builded.
  • Session ID is unique number and timeliness

Authorization 權限管理

  • Descide what user can and can't do, which is called Authorization

Make a session by Express

Tool

  • expressjs/session

https://github.com/expressjs/session

Reference