Add token exchange. Create token on server and use as a cookie on the client. We should use this as a default and issue a deprecation warning to anyone using the old methods. See: https://github.com/cdr/code-server/pull/3422#issuecomment-853297900 **Edit**: VS Code web already has token auth that we disable, could we make use of this? Then it should be pretty easy.