Store User Permissions (Identity: User / Admin / GBookUser / ArticleUser, etc.) should use the session, store username, password, configuration and other information, but cookie memory password is best to encrypt with MD5, because it is easy to be human Intercepted