Greating,
I Have a Web using ASP.net Core 3, and the Login method using MD5 Encript and only Using Session like this
if (Users.EMailAddress != ""