  • Session handling common requirement and not hard to implement
  • Implementation as HTTP middleware recommended
  • Handling credentials application-specific, may take advantage of database
  • See also authentication