  1. client post request with username password
  2.  server generates a random 128 bits session id, saves it into memory and responds with a html page containing the session id
  3.  client keeps the session id and send it with each request
  4.  server checks all requests for a session id before writing a html response
