Addresses three Important-severity review findings inherited from Task 4's
plan reference code:
- login() now sets secure=True on the session cookie (safe behind the
Cloudflare Tunnel, which terminates TLS at the edge).
- logout() looks up and deletes the matching AuthSession row before
clearing the cookie, so a leaked raw token can no longer be replayed
after logout.
- login() always performs exactly one verify_password call regardless of
whether the username exists (against a module-level dummy hash for
nonexistent users), removing the timing oracle that let unauthenticated
requests distinguish registered from unregistered usernames.
Adds two tests: nonexistent-username login rejection, and logout revoking
the session server-side. Also adjusts two cookie-propagation touch points
in test_auth.py to manually re-inject the qm_session cookie, since
httpx's cookie jar won't auto-attach a Secure cookie to the test
transport's plain http://test base_url (a real browser talking to the
HTTPS tunnel edge wouldn't have this problem).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof