ItsDangerous was used for application-owned, signed, time-limited authentication cookies. Login and session behavior passed the automated tests, with secrets kept in environment configuration.
- What worked
- It enabled portable session authentication without introducing a hosted identity dependency.