Hacker News new | ask | show | jobs
by xorcist 1362 days ago
> Just throw the session ID in as part of the payload

An authenticated session id is just a very very long session id.