AllFinance uses secure HTTP-only session cookies (`laravel-session` and `XSRF-TOKEN`) strictly for authentication and CSRF protection.