Accept X-***-Token for mobile clients in OTKPreAuthFilter

FeatureEmailService
Shipped
July 16, 2026 at 5:20 PM UTC
Author
Kamo
Commit
96accff

per-tab session id as X-***-Token (matching **************** When present (and no X-OTK), resolve the session non-consumingly and set the same request attributes; an invalid token sets nothing, so controllers still reject with 401. Session-data protection unchanged.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing