Add Authentication Constraints section - APIv2 stateless JWT, no CSRF, no cookies, forbidden patterns
This commit is contained in:
parent
d47e1c52a8
commit
6e353c381f
@ -41,3 +41,12 @@ They exist to prevent architectural drift, instability, and "demo-ware" UI patte
|
|||||||
- Brand: **ZeroLagHub**
|
- Brand: **ZeroLagHub**
|
||||||
- Shorthand: **ZLH**
|
- Shorthand: **ZLH**
|
||||||
- Gaming heritage is acceptable, esports aesthetic is not.
|
- Gaming heritage is acceptable, esports aesthetic is not.
|
||||||
|
|
||||||
|
## Authentication Constraints (APIv2)
|
||||||
|
|
||||||
|
- APIv2 authentication is stateless
|
||||||
|
- JWT tokens are issued by APIv2 only
|
||||||
|
- No CSRF protection is allowed
|
||||||
|
- No cookies are allowed for auth
|
||||||
|
- Portal stores tokens client-side (sessionStorage)
|
||||||
|
- APIv1 and Pterodactyl auth patterns are forbidden
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user