# Cookies session — first-party, HttpOnly, Secure, SameSite=Lax — stay logged in (necessary). csrf — form protection (necessary). No analytics cookies.
# Cookies session — first-party, HttpOnly, Secure, SameSite=Lax — stay logged in (necessary). csrf — form protection (necessary). No analytics cookies.