LearnAI ToolsCareerPractice BuildsPlayContact
Lesson 1520 min read

Session Management

Learn how HttpSession lets a JSP application remember a user across multiple requests, including storing, retrieving, and expiring session data.

Introduction

HTTP is stateless — every request arrives at the server with no memory of the last one. Yet most web applications need to remember who is logged in, what is in a shopping cart, or what step of a wizard the user reached. JSP and the Servlet API solve this with the session, a server-side storage area tied to a specific browser across multiple requests.

What You Will Learn
  • What a session is and how the server tracks it.
  • How to use the implicit session object in JSP.
  • How to store, read, and remove session attributes.
  • How to configure and understand session timeout.

What Is a Session?

When a browser first hits a JSP page, the server creates a unique session and sends the browser a cookie (typically named JSESSIONID) containing the session ID. On every subsequent request, the browser sends that cookie back, and the server uses it to look up the same session object — a private bucket of data that persists for that one user until it times out or is invalidated.

The session Implicit Object

Just like request and response, session is available automatically in every JSP page (it is backed by an instance of javax.servlet.http.HttpSession, or jakarta.servlet.http.HttpSession on newer servers). You do not need to create or import anything to use it.

Accessing the Implicit session Object
<%
// session is implicit — no declaration needed
String sessionId = session.getId();
%>
<p>Your session ID: <%= sessionId %></p>

Storing and Retrieving Attributes

Attributes are stored as key-value pairs, where the key is a String and the value can be any Java object. A login flow typically stores the logged-in username right after authentication succeeds.

login.jsp — Storing Session Data
<%
// login.jsp — after verifying credentials
session.setAttribute("username", "alexParker");
session.setAttribute("loginTime", new java.util.Date());
%>
dashboard.jsp — Reading Session Data with EL
<!-- dashboard.jsp — any later page in the same session -->
<p>Welcome back, ${sessionScope.username}!</p>
<p>You logged in at: <fmt:formatDate value="${sessionScope.loginTime}" type="both" /></p>
Rendered Output

Click Run to see what this code prints.

sessionScope in EL

sessionScope is EL's implicit map over session attributes, just like pageScope and requestScope you saw in earlier lessons. ${sessionScope.username} is equivalent to session.getAttribute("username") in a scriptlet.

Session Timeout

Sessions do not live forever. If a user is inactive for a configured period, the server discards the session to free memory and reduce the window a stolen cookie could be misused in. You can set the timeout in minutes per-session in Java, or globally in web.xml.

Setting Timeout Programmatically
<%
// Set timeout to 15 minutes for this session
session.setMaxInactiveInterval(15 * 60);
%>
web.xml — Global Session Timeout
<!-- web.xml — applies to all sessions in the application -->
<session-config>
<session-timeout>30</session-timeout> <!-- in minutes -->
</session-config>

Invalidating a Session

On logout, you should explicitly end the session rather than waiting for it to time out. invalidate() clears all attributes and marks the session dead — any later reference to it throws an exception.

logout.jsp
<%
// logout.jsp
session.invalidate();
response.sendRedirect("login.jsp");
%>

Common Mistakes

Avoid These Mistakes
  • Storing large objects (like an entire database result set) in the session, bloating server memory across every logged-in user.
  • Forgetting to call session.invalidate() on logout, leaving stale data reachable if the cookie is reused.
  • Assuming session data survives a server restart — in-memory sessions are lost unless the container is configured to persist them.
  • Relying on the session for data that should really be a database record, like a shopping cart that must survive days.

Best Practices

  • Store only small, essential data in the session — user ID, roles, a few UI preferences.
  • Always invalidate the session explicitly on logout.
  • Set a reasonable timeout — long enough not to annoy users, short enough to limit exposure.
  • Never store sensitive data like raw passwords in the session, even temporarily.

Frequently Asked Questions

Through the JSESSIONID cookie the server sets on the first response; the browser automatically returns it on every later request to that domain.

The container can fall back to URL rewriting (appending ;jsessionid=... to links), though this is rare in modern applications and cookies are strongly preferred.

No. Each browser gets its own isolated session; setAttribute in one user's session is invisible to everyone else.

Key Takeaways

  • A session lets the stateless HTTP protocol remember a user across requests.
  • The implicit session object is available in every JSP without setup.
  • sessionScope in EL reads session attributes declaratively.
  • Timeouts and invalidate() both control how long a session lives.

Summary

Sessions are the backbone of login systems, shopping carts, and multi-step forms in classic Java web apps. Next, you will look at cookies — the lower-level mechanism sessions are built on, and a tool you can also use directly for things like "remember me" preferences.

Next Lesson →

Cookies in JSP