- Ya
- 15 Juni 2026, 19:43 UTC
- Mwandishi
- kamo
- Ahadi ya
- 707243d
Rip out all the legacy-cookie clearing/migration. The token lives in sessionStorage (key ***) and travels as the X-***-Token header, which the backend already prefers — nothing else changes. The sign-out after login was the auth-bootstrap fetches (/api/user-info, session refresh/keepalive) firing on mount before the global fetch wrapper was in place, so they went out with no token. Pass the token explicitly on those calls instead of relying on the wrapper. validate no longer sets or clears any cookie.