ADR 0003: Same-origin cookie sessions; tokens only for the extension

Status: accepted

Decision

Consequences

Simple, robust auth with no third-party identity provider. Self-hosters must serve the app over HTTPS (any reverse proxy), because Secure cookies require it outside localhost.