Skip to content
Site updates

GGScore 2.4.0 — HttpOnly cookie sessions

7/20/2026, 1:19:18 PM

Cabinet auth moves off localStorage Bearer tokens: httpOnly Secure cookies, silent refresh, and CSRF for cookie-authenticated writes.

Version 2.4.0

Frontend and API ship the same semver.

What is new

  • HttpOnly cabinet sessions: access JWT (~1h) and refresh (~7d) live in Secure cookies — not localStorage.
  • POST /api/v2/auth/refresh: rotates refresh; reuse of a stolen refresh revokes all sessions for that user.
  • CSRF: double-submit cookie + X-CSRF-Token on mutating cabinet calls when authenticated via cookies.
  • Product API unchanged: match/data endpoints stay X-API-Key. The cabinet no longer promotes “Copy Bearer” as an API credential.

Why this matters

Session tokens are no longer readable by page JavaScript, which cuts XSS session theft for the cabinet while keeping the public API key model.

See also the repo CHANGELOG.md.

GGScore 2.4.0 changelog: HttpOnly cookie sessions | GGScore