From ca4f4be9c0d3d9fb8144d57e1d032abce2255d1e Mon Sep 17 00:00:00 2001 From: zkldi <20380519+zkldi@users.noreply.github.com> Date: Sun, 16 Oct 2022 23:54:19 +0100 Subject: [PATCH] fix: strict cookie settings also apply to staging at the moment they were only applied to prod, which means that browsers wont accept the login cookies this issue only affects staging lol --- server/src/server/server.ts | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/server/src/server/server.ts b/server/src/server/server.ts index 4eec8e49c..9056156fd 100644 --- a/server/src/server/server.ts +++ b/server/src/server/server.ts @@ -45,10 +45,16 @@ const userSessionMiddleware = expressSession({ cookie: { // the absence of Secure in combination with SameSite=None will cause issues on non-https // instances in newer versions of chromium. there is no workaround for this. - secure: Environment.nodeEnv === "production" || ServerConfig.ENABLE_SERVER_HTTPS, + secure: + Environment.nodeEnv === "production" || + Environment.nodeEnv === "staging" || + ServerConfig.ENABLE_SERVER_HTTPS, // Very important. Without this, we're vulnerable to CSRF! - sameSite: Environment.nodeEnv === "production" ? "strict" : "none", + sameSite: + Environment.nodeEnv === "production" || Environment.nodeEnv === "staging" + ? "strict" + : "none", }, });