diff --git a/server/package.json b/server/package.json index aa3c2e0e8..90b53e30e 100644 --- a/server/package.json +++ b/server/package.json @@ -1,6 +1,6 @@ { "name": "tachi-server", - "version": "2.0.19", + "version": "2.0.20", "description": "A score tracking server.", "main": "js/index.js", "private": true, diff --git a/server/src/lib/constants/version.ts b/server/src/lib/constants/version.ts index db328ccd3..068113853 100644 --- a/server/src/lib/constants/version.ts +++ b/server/src/lib/constants/version.ts @@ -4,7 +4,7 @@ const MAJOR = 2; const MINOR = 0; -const PATCH = 19; +const PATCH = 20; // As is with all front-facing zkldi projects, the version names for tachi-server // are from an album I like. In this case, the album is Portishead - Dummy. diff --git a/server/src/server/server.ts b/server/src/server/server.ts index 40bc10a02..4f62cd32d 100644 --- a/server/src/server/server.ts +++ b/server/src/server/server.ts @@ -37,7 +37,7 @@ const userSessionMiddleware = expressSession({ saveUninitialized: false, cookie: { secure: Environment.nodeEnv === "production" || ServerConfig.ENABLE_SERVER_HTTPS, - sameSite: "lax", // Very important. Without this, we're vulnerable to CSRF! + sameSite: "strict", // Very important. Without this, we're vulnerable to CSRF! }, });