Auth and session flaws
We review weak JWT secrets, missing rate limits, and insecure session patterns that show up in code and config.
Login is the front door. Soft session handling is how accounts get guessed, replayed, or shared without you noticing.