HTTP Basic Auth question – Information Security Stack Exchange


I am using HTTP Basic Auth to authenticate the user.
Once authenticated, I set req.session.loggedIn = true.
If a user makes requests after being logged in, for security purposes, should I just check the session loggedIn value or send the basic auth header on each request and then verify credentials on each request on my backend?