|
|
20c2fcd496
|
Harden auth with revocable sessions, cookies, and single-login default.
Issue short-lived access JWTs backed by AuthSession rows, HttpOnly cookies with refresh rotation, idle timeout, session management UI, WebCRT ownership caps, and optional Redis login rate limits; new logins revoke other sessions by default.
Co-authored-by: Cursor <cursoragent@cursor.com>
|
2026-08-06 14:13:37 +08:00 |
|