Redirect to login instead of 401 on unauthorized/not-fresh sessions (Flask-Login handlers) 6de8fab David Ko commited on Aug 14
Redirect-on-expiry: fresh required on /api/status and injected heartbeat in index.html responses to auto-redirect to /login when session expires 630e9fb David Ko commited on Aug 14
Security/session hardening: absolute 2-min expiry (SESSION_REFRESH_EACH_REQUEST=False), disable remember, anti-autofill login form, no-store cache on protected routes, clear session on logout b4662d6 David Ko commited on Aug 14
Enforce 2-minute session expiry: set PERMANENT_SESSION_LIFETIME=120s via timedelta and disable remember-login ac9962b David Ko commited on Aug 14
Adjust session cookie SameSite=None and set PERMANENT_SESSION_LIFETIME=120s for testing 2937552 David Ko commited on Aug 14
Use SameSite=None for session/remember cookies (iframe compatibility on Spaces) d1b4a04 David Ko commited on Aug 14
Fix login redirect loop with improved session handling and debugging dfdf7e7 David Ko commited on Aug 14
Fix login redirect loop by improving login and serve_react functions 64663bd David Ko commited on Aug 14