Why: standardize session login/refresh/logout/me behavior for web clients behind thalos security boundaries. What: add canonical routes, cookie policy handling, grpc session calls, compatibility aliases, standardized auth errors, updated contracts, tests, and docs. Rule: keep BFF as edge adapter over service contracts and preserve identity ownership in thalos. |
||
|---|---|---|
| .. | ||
| api | ||
| architecture | ||
| migration | ||
| runbooks | ||
| security | ||