- trust proxy for correct IP behind nginx - refresh token now set as httpOnly cookie alongside access token - GET /api/auth/refresh-session for browser-based token refresh - DELETE /api/auth/me with full cleanup of tokens and cookies - rate limiting on login (10/15min) and register (5/hr) - welcome email on registration (non-blocking) - delete account UI on profile page with two-step confirm Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| middleware | ||
| routes | ||
| db.ts | ||
| index.ts | ||
| rateLimiter.ts | ||
| roles.ts | ||