The Runtime Theory
ServerInternalsexecution

Trace: Authentication, Sessions, and Authorization

Follow the key state changes and boundary checks involved in authentication, sessions, and authorization.

The Runtime Theory Team8 min read05 steps

layer stack

Server

HWHardware
KKernel
RTRuntime
APPApplication
SYSSystem
CLIClient
NETNetwork
TLSCrypto
SRVServer

trace spine

  1. 01 Verify credentials or token
  2. 02 Resolve session identity
  3. 03 Authorize the resource
  4. 04 Perform the permitted operation
  5. 05 Expire or revoke session state
▸ On this page

This trace follows the actual state transitions behind the companion Authentication, Sessions, and Authorization. It describes a common execution path; implementation details can vary, so keep the contract separate from the mechanism.

Step 1: Verify credentials or token

Authentication answers who or what is making a request; authorization decides which actions that identity may perform on a resource. A session binds later requests to an authenticated context. Keeping these decisions separate makes access rules easier to audit and change.

Step 2: Resolve session identity

After login, a server can create a random session identifier and store session state server-side, sending the identifier in a protected cookie. On each request, it resolves the session and checks whether the user may access the requested object. Object ownership must be checked at the resource boundary, not inferred from a hidden UI link.

Step 3: Authorize the resource

After identifying the caller, check permission against the specific requested object; knowing a valid session must not make a guessed resource identifier accessible.

At this point, record the state that changed and check the invariant before advancing. If the operation repeats, make clear which values persist and which are recomputed.

Step 4: Perform the permitted operation

Signed tokens can reduce lookup needs but complicate revocation, expiration, and claim freshness. Cookies need secure transport and appropriate SameSite and HttpOnly settings. Authentication success alone must never imply permission to read every record associated with a guessed identifier.

Step 5: Expire or revoke session state

A user changes a URL from /orders/123 to /orders/124 and sees another account’s order. Identify the missing server-side check and one test that would catch the flaw.

The trace is complete when the result satisfies the stated contract. Compare this model with the concrete runtime or system you are studying before making a performance claim.

Not started

Sign in to save your learning progress.

Sign in to save