Stop touching cookies; send token explicitly on auth calls

Fixkamo-internal
Shipped
June 15, 2026 at 7:43 PM UTC
Author
kamo
Commit
707243d

Rip out all the legacy-cookie clearing/migration. The token lives in sessionStorage (key ***) and travels as the X-***-Token header, which the backend already prefers — nothing else changes. The sign-out after login was the auth-bootstrap fetches (/api/user-info, session refresh/keepalive) firing on mount before the global fetch wrapper was in place, so they went out with no token. Pass the token explicitly on those calls instead of relying on the wrapper. validate no longer sets or clears any cookie.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing