ArchitectureSecurity model
The session cookie
After you sign in, a cookie proves who you are. The JavaScript of the page cannot read it.
You sign in at /login with your email and your password.
1 / 4
A session is the proof that one browser signed in. The browser keeps it in the session cookie.
The cookie
| Property | Effect |
|---|---|
HttpOnly | The JavaScript of the dashboard cannot read the cookie. |
SameSite=Strict | The browser sends the cookie only with requests from the same site. |
Secure | Set when you reach the dashboard over HTTPS through a proxy. |
The name ferry_session_7878 | The name ends with the port of the address that you use. |
When a session ends
- 30 days after its last use.
- When you sign out.
- When you change the password: the session of each other browser ends.
In the dashboard, Server → Account lists the sessions. There, you can sign each browser out.
The servers 127.0.0.1:7878 and 127.0.0.1:7879 have the same host name. Because the name of the cookie ends with the port, each server keeps its own session.
The dashboard keeps only UI preferences in localStorage. The secret of the session is only in the cookie.