9d3b8e6351
Sessions move from the in-memory map to a `sessions` table (migration 0002), so a restart, a redeploy or a restore from a full backup no longer signs the administrator out. The row holds a SHA-256 of the token rather than the token itself: a stolen database file or backup archive cannot be replayed into a login, while the browser that still holds the cookie keeps working across a restore. The 12-hour absolute TTL becomes a sliding 7-day idle window, configurable through PANEL_SESSION_IDLE_DAYS (whole days, mirroring SEND_LOG_RETENTION_DAYS). No absolute cap: for an administrator who visits regularly the session lasts indefinitely, which is the accepted trade-off. The four `every 5s` monitoring fragments deliberately do not renew it — otherwise a forgotten open tab would hold the session open forever and the window would mean "seven days without an open tab" rather than "seven days without the administrator". Decision only; no code yet. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>