jwtMiddleware now rotates the access-token cookie proactively when within PROACTIVE_REFRESH_MARGIN_SEC (15 min) of real expiry, using the server's own clock. Removes the need for client-side exp comparison (impossible anyway for httpOnly cookies). AuthPayload gains iat/exp fields for callers that need to inspect token lifetime. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| source | ||
| workspace | ||