Users authenticate via JWT tokens with automatic refreshsarah.
Cookies use SameSite=Strict to mitigate CSRF.
export function verify(token: string) { return jwt.verify(token, SECRET) }