Overview
by Aarav Sharma
We moved session checks to the edge to cut latency on every page load.
It worked in staging, then failed on preview deploys when cookies crossed domains.
Clock skew between edge and origin made short-lived tokens look expired.
We fixed cookie domains per environment and added skew-tolerant expiry.
Median auth path dropped about 120ms, with fewer cold-start surprises.
Lesson: test cookies across every environment before calling a migration done.