However the client can edit cookies that are stored in the web browser so expiring sessions on the server is safer. Rails Guides <https://guides.rubyonrails.org/security.html> - > The best practice is to use a database based session OWASP Cheet Sheet Series: Ruby on Rails Cheet Sheet <https://cheatsheetseries.owasp.org/cheatsheets/Ruby_on_Rails_Cheat_Sheet.html#sessions> - セッションをサーバサイドに切り替えよう