Modify all frontend API calls to include JWT auth tokens and handle authentication errors gracefully.
Implementation Tasks
Store JWT token after successful magic link authentication
Add Authorization header to all API requests
Handle 401 responses (redirect to login)
Handle token expiration (refresh or re-authenticate)
Clear token on logout
Security Considerations
Store token in memory or httpOnly cookie (not localStorage for XSS protection)
Clear token on tab close if using memory storage
Handle CORS correctly for API requests
Acceptance Criteria
All API calls include valid auth token
401 responses trigger re-authentication flow
Token is stored securely
Logout clears authentication state
## Summary
Modify all frontend API calls to include JWT auth tokens and handle authentication errors gracefully.
## Implementation Tasks
- [x] Store JWT token after successful magic link authentication
- [x] Add Authorization header to all API requests
- [x] Handle 401 responses (redirect to login)
- [x] Handle token expiration (refresh or re-authenticate)
- [x] Clear token on logout
## Security Considerations
- Store token in memory or httpOnly cookie (not localStorage for XSS protection)
- Clear token on tab close if using memory storage
- Handle CORS correctly for API requests
## Acceptance Criteria
- [x] All API calls include valid auth token
- [x] 401 responses trigger re-authentication flow
- [x] Token is stored securely
- [x] Logout clears authentication state
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Modify all frontend API calls to include JWT auth tokens and handle authentication errors gracefully.
Implementation Tasks
Security Considerations
Acceptance Criteria