Because there is not much to explain.
You don't login with a session, instead the session gets created by you logging in.
You take the dosid from your cookies and place it in your applications cookie jar or whatever you are using. Now you can access the internal pages as this specific user.
Since HTTP is stateless the socket can't really tell who you are so it identifies you by an id that you transmit on every request.
If you are interested in the topic, you can look into stateless protocols and the idea behind sessions, cookies etc. but the info above should already be enough to get a general idea.