- Refactor system to use post requests instead of get requests - Have the server generate a session-id and send it to the client - Make sure the session-id is added to every post request