Add CSRF Protection

This commit is contained in:
zkldi
2021-09-04 11:16:05 +01:00
parent 9868816c4d
commit 3d56613ddc
+1
View File
@@ -33,6 +33,7 @@ const userSessionMiddleware = expressSession({
saveUninitialized: false,
cookie: {
secure: process.env.NODE_ENV === "production" || ServerConfig.ENABLE_SERVER_HTTPS,
sameSite: "lax", // Very important. Without this, we're vulnerable to CSRF!
},
});