mirror of
https://github.com/zkldi/Tachi.git
synced 2026-09-30 02:48:01 +03:00
Add CSRF Protection
This commit is contained in:
@@ -33,6 +33,7 @@ const userSessionMiddleware = expressSession({
|
||||
saveUninitialized: false,
|
||||
cookie: {
|
||||
secure: process.env.NODE_ENV === "production" || ServerConfig.ENABLE_SERVER_HTTPS,
|
||||
sameSite: "lax", // Very important. Without this, we're vulnerable to CSRF!
|
||||
},
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user