- Implement register, login, logout, and me endpoints
- Use bcryptjs for password hashing
- HTTPOnly secure cookies for sessions (Lucia Auth pattern)
- Users and sessions tables with proper relations
- 7-day session duration with auto-expiry
Co-Authored-By: Claude Sonnet 4.5 (1M context) <noreply@anthropic.com>