f5d17de1d2
- validate cookie format - check if token was found first before validation to prevent race condition - separate the expired/ip/user agent check for different handling