ποΈ
Resource Server
:3002
1
POST
/auth/login
{ username, password }
2
200
{ accessToken } + Set-Cookie
refresh_token β httpOnly, 7 days
3
GET
/api/*
Authorization: Bearer <token>
4
200
/ 401 / 403
data or token / role error
5
POST
/auth/refresh
cookie sent automatically by browser
6
200
{ newAccessToken } + rotated cookie
old refresh token revoked
Steps 3 β 6 happen in the app after login