Since it could always happen that someone leaks their session ID stored in the URL (screenshot, browser history) we should set a cookie for that.