Security foundation

Protection built into the structure.

WFeels begins with secure sessions, CSRF protection, safe output, strict headers and a clean separation between public, doctor, patient and admin areas.

Secure sessions

Strict cookie mode, HTTP-only cookies, SameSite protection and session rotation readiness.

Request protection

CSRF tokens, content-security policy, protected form actions and safe output encoding.

Separated roles

Independent page areas for admins, clinicians and patients, ready for server-side authorization.

Saved for the functional phase.