- Add sessions table to store session tokens with expiration - Create Session domain model and SessionRepository trait - Implement SqlSessionRepository for session persistence - Update is_authenticated() to validate tokens against database - Sessions expire after 30 days - Session tokens hashed with SHA-256 before storage - Delete sessions from database on logout - Update all page handlers to properly validate sessions This prevents session hijacking by ensuring only valid, unexpired tokens stored in the database can authenticate requests. Co-authored-by: jnsgruk <668505+jnsgruk@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| 0001_init.sql | ||
| 0002_auth.sql | ||
| 0003_sessions.sql | ||