I wrote a express middleware to implement refresh/access token auth using jwt. My middle-ware is setting generated secure tokens as cookie variables in to the http client an