Members and applications should be different types in the API
Frontend throws internal server errors if it gets an invalid token from a cookie
Frontend queries permissions really often
Users can also gain new permissions and the cache should also be invalidated when that happens.
Frontend queries permissions really often
Invalid credentials throw an internal server error