I'll audit the checkout flow for authentication gaps. First, let me sync the latest commits from the repository and map every module that reads or writes session state.
.env.example LICENSE checkout-guard.ts checkout-guard.test.ts guard.ts session-token-guard.ts session-token.test.ts session-token.ts webhook-guard.ts