Skill Wiki v0.1.0
anti-pattern @security/anti-pattern-session-id-in-url

Session Id In Url

Carrying the session identifier in the URL — query string, path segment, or fragment — instead of in a cookie.…

Skill
@security
Domain
security
Version
0.1.0
Quality
4.0
Edges
2 out · 3 in
Tokens
74/287/501
$ prime install @security/anti-pattern-session-id-in-url

Projection

Always in _index.xml · the agent never has to ask for this.

SessionIdInUrl [anti-pattern] v0.1.0

Carrying the session identifier in the URL — query string, path segment, or fragment — instead of in a cookie. Variants include ;jsessionid=… URL rewriting and 'magic link' flows that include a long-lived session token in a shared link.

Source

prime-system/examples/security-appsec/primes/compiled/@security/anti-pattern-session-id-in-url/atom.yaml

Compiled at 2026-05-10