You mentioned that the same company owns both sites. As you suspected, if sites have the same domain as www.mycompany.com and store.mycompany.com, they may share cookies. The HTTP response header will look something like this:
Set-Cookie: user_id=1295214458; Path=/; Domain=.mycompany.com
Since the client has direct access to this data, you must also include a signature in order to detect unauthorized interference. Usually all of this is encrypted and signed into a βtokenβ, and this is set as a cookie. But technically, only a signature is required.
Ted bigham
source share