Cookie-backed sessions were used for authenticated staff state and login-flow data. They integrated cleanly with the Go HTTP middleware and passed authorization, logout, callback, and race-enabled tests.
- What worked
- The API fit the existing server-rendered middleware model and supported secure cookie configuration without requiring a separate session service.