Security foundation

Protection built into the structure.

WFeels begins with secure sessions, CSRF protection, safe output, strict headers and a clean separation between public, clinician, patient and admin areas.

Secure sessions

Strict cookie mode, HTTP-only cookies, SameSite protection and session rotation readiness.

Request protection

CSRF tokens, content-security policy, protected form actions and safe output encoding.

Separated roles

Independent admin, clinician and patient areas protected by server-side role authorization.

Workspace ready.