GGScore 2.4.0 — HttpOnly cookie sessions
7/20/2026, 1:19:18 PM
Cabinet auth moves off localStorage Bearer tokens: httpOnly Secure cookies, silent refresh, and CSRF for cookie-authenticated writes.
Version 2.4.0
Frontend and API ship the same semver.
What is new
- HttpOnly cabinet sessions: access JWT (~1h) and refresh (~7d) live in Secure cookies — not
localStorage. POST /api/v2/auth/refresh: rotates refresh; reuse of a stolen refresh revokes all sessions for that user.- CSRF: double-submit cookie +
X-CSRF-Tokenon mutating cabinet calls when authenticated via cookies. - Product API unchanged: match/data endpoints stay
X-API-Key. The cabinet no longer promotes “Copy Bearer” as an API credential.
Why this matters
Session tokens are no longer readable by page JavaScript, which cuts XSS session theft for the cabinet while keeping the public API key model.
See also the repo CHANGELOG.md.