• Steven's avatar
    refactor(auth): remove legacy session cookie authentication · a6c32908
    Steven authored
    - Remove SessionCookieName and SessionSlidingDuration constants
    - Remove ExtractSessionCookieFromHeader() function
    - Remove SessionIDContextKey and GetSessionID() function
    - Remove sessionID parameter from SetUserInContext()
    - Remove SessionID field from AuthResult struct
    - Remove session cookie extraction from middleware
    - Update documentation to reflect JWT + PAT only auth
    
    Session cookies were never being set since migration to refresh token
    authentication. This change removes ~50 lines of dead code and clarifies
    that the system uses JWT access tokens, refresh tokens, and PATs only.
    a6c32908
Name
Last commit
Last update
.github Loading commit data...
cmd/memos Loading commit data...
internal Loading commit data...
plugin Loading commit data...
proto Loading commit data...
scripts Loading commit data...
server Loading commit data...
store Loading commit data...
web Loading commit data...
.dockerignore Loading commit data...
.gitignore Loading commit data...
.golangci.yaml Loading commit data...
CLAUDE.md Loading commit data...
CODEOWNERS Loading commit data...
LICENSE Loading commit data...
README.md Loading commit data...
SECURITY.md Loading commit data...
go.mod Loading commit data...
go.sum Loading commit data...