>>I am almost obsessing over web security ..
If you need more security why not use https all the time and better use two factor authentication?
BTW, would you mind explaining what is a client side session? Share a link may be? Really, I have never heard of them-