Part 18 · Applications

Sessions, browser credentials and CSRF

Prerequisites: 01-ecosystem

How do sessions survive replica changes?

Browser: cookie + CSRF token; App replica A: session integration; App replica B: session integration; Shared session store: expiry + state. Connections: Browser to App replica A (request); Browser to App replica B (next request); App replica A to Shared session store (load / save); App replica B to Shared session store (load / save)
A shared session store is an option, not mandatory for every app. CSRF still depends on credential transport. [S34] [S35]

Goal & mental model verified

Spring Session externalizes session handling through shared implementations. CSRF is about a browser automatically attaching credentials to a forged request; it is not solved by calling the API “REST.”

[S34] [S35]

Worked example · design exercise synthesis

A browser broker portal uses a session cookie and CSRF token on state-changing requests. Two app replicas can access shared session state instead of relying solely on one process’s memory.

[S34] [S35]

Engineering decision synthesis

Choose session or bearer-token flows from client and threat requirements. Shared sessions improve replica mobility but introduce storage availability, expiration and serialization concerns.

[S34] [S35]

Pitfall & diagnosis synthesis

Stateless does not automatically mean CSRF-safe if browser credentials are still sent automatically. CORS policy is not a replacement for CSRF protection.

[S34] [S35]

Improve & validate synthesis

Exercise expiration, logout, replica changes and state-changing cross-origin requests. Confirm credential behavior and token checks for the actual browser flow.

[S34] [S35]
Keep this: Understand how credentials travel before disabling protections.
Check yourself: Why can a cookie API need CSRF protection?

Because a browser can automatically attach the cookie to a forged request.

Sources & further reading

  1. [S34] CSRF protection

    Spring project maintainers · documentation · accessed 2026-10-09 · Documentation retrieved 2026-10-09

    Supports: Browser ambient credentials; CSRF threats and tokens

    Read the linked section to validate the mechanism and its version-specific constraints.

  2. [S35] Spring Session

    Spring project maintainers · documentation · accessed 2026-10-09 · Documentation retrieved 2026-10-09

    Supports: Session abstraction; Shared session implementations

    Read the linked section to validate the mechanism and its version-specific constraints.