Essential session
The cookie is HTTP-only, SameSite=Lax and marked Secure when HTTPS is active.
No marketing trackers
The supplied implementation does not load analytics pixels or behavioral advertising scripts.
The application uses one first-party session cookie for authentication, CSRF state and session rate limiting. No advertising or third-party analytics cookies are included.
The cookie is HTTP-only, SameSite=Lax and marked Secure when HTTPS is active.
The supplied implementation does not load analytics pixels or behavioral advertising scripts.