Hi


I assume, you are dealing successfully with the servlet API[1-3]
for the authentication, managing/tracking of the state or sessions.
You are here interested in the security implications...