fix: strict cookie settings also apply to staging

at the moment they were only applied to prod,
which means that browsers wont accept the login cookies

this issue only affects staging
lol
This commit is contained in:
zkldi
2022-10-16 23:54:19 +01:00
parent ffb776e691
commit ca4f4be9c0
+8 -2
View File
@@ -45,10 +45,16 @@ const userSessionMiddleware = expressSession({
cookie: {
// the absence of Secure in combination with SameSite=None will cause issues on non-https
// instances in newer versions of chromium. there is no workaround for this.
secure: Environment.nodeEnv === "production" || ServerConfig.ENABLE_SERVER_HTTPS,
secure:
Environment.nodeEnv === "production" ||
Environment.nodeEnv === "staging" ||
ServerConfig.ENABLE_SERVER_HTTPS,
// Very important. Without this, we're vulnerable to CSRF!
sameSite: Environment.nodeEnv === "production" ? "strict" : "none",
sameSite:
Environment.nodeEnv === "production" || Environment.nodeEnv === "staging"
? "strict"
: "none",
},
});