Best Practice for Storing User Session

Have you thought about using a JWT?

See: