Goal
Move auth from session cookies to JWT across api/. Keep the existing tests green.
Done
- Added
src/lib/jwt.tswith sign and verify helpers - Swapped cookie middleware for JWT in
auth.ts - Migrated 9 of 12 route handlers
Blocked on
tests/auth.spec.ts:48 expected 401, got 500. verify() throws on expired tokens instead of returning null.
Next step
Catch TokenExpiredError at src/lib/jwt.ts:22, return null, then run npm test auth.
Changed files
src/lib/jwt.ts +41 api/middleware/auth.ts +18 −27 api/routes/*.ts +64 −88