Potential security issue with Frontend Token Autentication

Latest conversations here and next to the code repository have led to many improvements in the code base which respect the rationales above, and caused a new release v0.9.0.

It was also influenced by thoughts in Rereading Documentation: Client arguments largely redundant? - #4 by yala