Is this SPA authentication flow secure?