With AUTH_SEND_JWT_HEADER=true, frontend now properly handles JWT authentication: - Store JWT token in client-side cookie named 'JWT' - Extract and store XSRF token from JWT payload - Set Secure flag automatically when on HTTPS connection - Update documentation to clarify this behavior This fixes an issue where login state would be lost after page reload when using header-based JWT authentication.