mirror of
https://github.com/zkldi/Tachi.git
synced 2026-09-29 10:28:04 +03:00
fix: strict cookie settings also apply to staging
at the moment they were only applied to prod, which means that browsers wont accept the login cookies this issue only affects staging lol
This commit is contained in:
@@ -45,10 +45,16 @@ const userSessionMiddleware = expressSession({
|
||||
cookie: {
|
||||
// the absence of Secure in combination with SameSite=None will cause issues on non-https
|
||||
// instances in newer versions of chromium. there is no workaround for this.
|
||||
secure: Environment.nodeEnv === "production" || ServerConfig.ENABLE_SERVER_HTTPS,
|
||||
secure:
|
||||
Environment.nodeEnv === "production" ||
|
||||
Environment.nodeEnv === "staging" ||
|
||||
ServerConfig.ENABLE_SERVER_HTTPS,
|
||||
|
||||
// Very important. Without this, we're vulnerable to CSRF!
|
||||
sameSite: Environment.nodeEnv === "production" ? "strict" : "none",
|
||||
sameSite:
|
||||
Environment.nodeEnv === "production" || Environment.nodeEnv === "staging"
|
||||
? "strict"
|
||||
: "none",
|
||||
},
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user