* fix: encrypt the cookie in sessions * tests: use new auth config in tests * fix: coderabbit suggestions