From 96481369da42e91a53030291c953dc9b0f4144d2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Y=C3=BBki=20VACHOT?= Date: Wed, 29 Dec 2021 18:39:15 +0100 Subject: [PATCH] Update: Add sameSite Cookie --- config/sessionJWT.config.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/sessionJWT.config.js b/config/sessionJWT.config.js index 64e1488..be7ae00 100644 --- a/config/sessionJWT.config.js +++ b/config/sessionJWT.config.js @@ -42,7 +42,7 @@ function createSessionCookie(req, res, payload) { else { jwtToken = createSessionJWT(payload.id, payload.email, payload.profileImageUrl, payload.role); } - res.cookie('SESSIONID', jwtToken, {httpOnly: true, secure: process.env.NODE_ENV === "production"}); + res.cookie('SESSIONID', jwtToken, {httpOnly: true, sameSite: 'strict', secure: process.env.NODE_ENV === 'production'}); } function decodeSessionCookie(sessionid) {