- Session stored as an encrypted (JWE) httpOnly cookie; access/refresh tokens
never reach the client, client_secret never leaves the server.
- winofyFetch: server-side API client matching FRONTEND_GUIDE.md's plain-success
/ wrapped-error (§4.1-4.2) convention, with auto token refresh.
- Login page (phone -> OTP) wired to Gooyal accounts staging; request_otp
verified working end-to-end. Token exchange returns invalid_client with the
client_id/secret currently on hand — needs a fix from whoever issued them.
- proxy.ts (Next 16's renamed middleware) gates seller/cart/checkout/orders
routes, verified redirecting unauthenticated requests to /login.
- Customer home page renders real store/category data fetched live from
winofy-staging.winsoo.ir.