Auth for Web Apps: Cookies, JWTs, and Sessions (Correctly) Security-focused guidance with modern defaults.