[web] Disable secure cookies
This commit is contained in:
parent
bb7168f522
commit
384bf03688
@ -56,7 +56,8 @@ export async function attemptLogin(
|
|||||||
if (user.passwordHash === hash.hash.toString()) {
|
if (user.passwordHash === hash.hash.toString()) {
|
||||||
const session = await db.session.create({ data: { userId: user.id } });
|
const session = await db.session.create({ data: { userId: user.id } });
|
||||||
cookies.set('session', session.token, {
|
cookies.set('session', session.token, {
|
||||||
secure: process.env.NODE_ENV === 'development' ? false : true,
|
// secure: process.env.NODE_ENV === 'development' ? false : true,
|
||||||
|
secure: false,
|
||||||
httpOnly: true,
|
httpOnly: true,
|
||||||
sameSite: 'strict',
|
sameSite: 'strict',
|
||||||
maxAge: sessionExpireSeconds
|
maxAge: sessionExpireSeconds
|
||||||
|
Loading…
Reference in New Issue
Block a user