diff --git a/config/sessionJWT.config.js b/config/sessionJWT.config.js index 64e1488..be7ae00 100644 --- a/config/sessionJWT.config.js +++ b/config/sessionJWT.config.js @@ -42,7 +42,7 @@ function createSessionCookie(req, res, payload) { else { jwtToken = createSessionJWT(payload.id, payload.email, payload.profileImageUrl, payload.role); } - res.cookie('SESSIONID', jwtToken, {httpOnly: true, secure: process.env.NODE_ENV === "production"}); + res.cookie('SESSIONID', jwtToken, {httpOnly: true, sameSite: 'strict', secure: process.env.NODE_ENV === 'production'}); } function decodeSessionCookie(sessionid) {