A method and apparatus for securing hypertext transfer protocol sessions authenticates
a user's credentials before creating a session. The present invention then associates
the session with the credentials. Subsequent requests are submitted with the session
ID and the user credentials to be associated with the session. Therefore, an unauthorized
user that has obtained a session ID cannot gain access to sensitive content associated
with the session without possessing the valid credentials.