See Spring Boot security. - [ ] With JWT + cookies on front - [ ] 2 factors TOTP - [ ] Long session with token regeneration - [ ] Postponed: - [ ] User API keys - [ ] Security audit