fix: standardize session cookie sameSite attribute and ensure proxy setting for production

This commit is contained in:
ethanf 2025-08-16 12:48:23 -05:00
parent 78e3e6b092
commit 6f3647a64b

View File

@ -63,9 +63,10 @@ app.use(session({
secure: process.env.NODE_ENV === 'production', secure: process.env.NODE_ENV === 'production',
maxAge: 24 * 60 * 60 * 1000, // 24 hours maxAge: 24 * 60 * 60 * 1000, // 24 hours
httpOnly: true, httpOnly: true,
sameSite: process.env.NODE_ENV === 'production' ? 'lax' : 'lax' sameSite: 'lax'
}, },
name: 's22poll.sid' name: 's22poll.sid',
proxy: process.env.NODE_ENV === 'production'
})); }));
app.use(passport.initialize()); app.use(passport.initialize());