I’m currently building authentication for an app. When user signs up or signs in both refresh token and access token are set in cookies and on each request I check if access