From 384bf036885f8411a1192a1d16a9c5b63ad947ae Mon Sep 17 00:00:00 2001 From: orosmatthew Date: Sun, 15 Oct 2023 15:00:32 -0400 Subject: [PATCH] [web] Disable secure cookies --- web/src/lib/server/auth.ts | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/web/src/lib/server/auth.ts b/web/src/lib/server/auth.ts index 236e83f..d2996a7 100644 --- a/web/src/lib/server/auth.ts +++ b/web/src/lib/server/auth.ts @@ -56,7 +56,8 @@ export async function attemptLogin( if (user.passwordHash === hash.hash.toString()) { const session = await db.session.create({ data: { userId: user.id } }); cookies.set('session', session.token, { - secure: process.env.NODE_ENV === 'development' ? false : true, + // secure: process.env.NODE_ENV === 'development' ? false : true, + secure: false, httpOnly: true, sameSite: 'strict', maxAge: sessionExpireSeconds