Loading post…
Loading post…
30 Aug 20261 min read
Secure cookies, CSRF-safe flows and token hygiene that survive real users.
// verify, then decide. Everything else is decoration.
const { payload } = await jwtVerify(token, secret);
if (payload.sub !== "admin") throw new Error("nope");
Auth code should be boring to read and annoying to bypass.
Links