Document session cookie security behavior
This commit is contained in:
@@ -47,6 +47,7 @@ Fresh full-stack starter scaffold:
|
||||
## Implemented Backend Scope
|
||||
|
||||
- Auth: register, login, logout, current user context
|
||||
- Session cookie: `HttpOnly`, `SameSite=Strict`, `Secure` when served over HTTPS
|
||||
- Rulesets: d6 and dnd5e validation rules
|
||||
- Campaigns: create/list/read
|
||||
- Characters: create/update/activate/current-campaign list
|
||||
|
||||
Reference in New Issue
Block a user