Cookie-backed auth. No localStorage, no token juggling, just a same-origin session.
Session cookies stay on the browser and are sent with each request.