Well, if implemented right. Techically every ssl connection would carry user's identity so cookie with that identity wouldn't even be required
Sounds like token binding.
Well, if implemented right. Techically every ssl connection would carry user's identity so cookie with that identity wouldn't even be required