Commit Graph

1 Commits

Author SHA1 Message Date
sulthan 7d0eaaef02 feat(backend): stateless HMAC session cookies for the web UI
Adds sessionKey/signSession/verifySession primitives and
setSessionCookie/clearSessionCookie helpers in a new backend/session.go.
Sessions are derived from API_TOKEN via HMAC-SHA256 with domain
separation (sessionKeyPurpose), so there is no session table and
rotating the token invalidates every outstanding cookie at once.
No routes or handlers yet — that's task 5.
2026-07-25 22:45:52 +07:00