Skip to content

Remove client-side authToken cookie handling and rely on secure server cookie #35

@KGFCH2

Description

@KGFCH2

Summary

Eliminate insecure client-side auth token storage during login and use secure cookie-based auth instead.

Details

  • Removes client-side authToken cookie writes
  • Uses server-managed authentication cookies
  • Improves security posture

Acceptance Criteria

  • No auth token is stored in browser cookies from client code
  • Login still succeeds via secure cookie
  • Auth flow remains functional

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions