memos/server/auth
Steven a6c32908a0 refactor(auth): remove legacy session cookie authentication
- Remove SessionCookieName and SessionSlidingDuration constants
- Remove ExtractSessionCookieFromHeader() function
- Remove SessionIDContextKey and GetSessionID() function
- Remove sessionID parameter from SetUserInContext()
- Remove SessionID field from AuthResult struct
- Remove session cookie extraction from middleware
- Update documentation to reflect JWT + PAT only auth

Session cookies were never being set since migration to refresh token
authentication. This change removes ~50 lines of dead code and clarifies
that the system uses JWT access tokens, refresh tokens, and PATs only.
2025-12-19 00:09:08 +08:00
..
authenticator.go refactor(auth): remove legacy session cookie authentication 2025-12-19 00:09:08 +08:00
context.go refactor(auth): remove legacy session cookie authentication 2025-12-19 00:09:08 +08:00
extract.go refactor(auth): remove legacy session cookie authentication 2025-12-19 00:09:08 +08:00
token.go refactor(auth): remove legacy session cookie authentication 2025-12-19 00:09:08 +08:00
token_test.go refactor: user auth improvements (#5360) 2025-12-18 18:15:51 +08:00