Why: standardize session login/refresh/logout/me behavior for web clients behind thalos security boundaries. What: add canonical routes, cookie policy handling, grpc session calls, compatibility aliases, standardized auth errors, updated contracts, tests, and docs. Rule: keep BFF as edge adapter over service contracts and preserve identity ownership in thalos. |
||
|---|---|---|
| .. | ||
| ContractShapeTests.cs | ||
| IssueTokenHandlerTests.cs | ||
| RefreshSessionHandlerTests.cs | ||
| Thalos.Bff.Application.UnitTests.csproj | ||