http://stackoverflow.com/questions/10960131/authentication-authorization-and-session-management-in-traditional-web-apps-and