Skip to content

Commit bc30bd1

Browse files
authored
set sameSite to lax when allowing insecure cookies (#1078)
1 parent 745e51e commit bc30bd1

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

src/lib/server/auth.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ export function refreshSessionCookie(cookies: Cookies, sessionId: string) {
5555
cookies.set(COOKIE_NAME, sessionId, {
5656
path: "/",
5757
// So that it works inside the space's iframe
58-
sameSite: dev ? "lax" : "none",
58+
sameSite: dev || ALLOW_INSECURE_COOKIES === "true" ? "lax" : "none",
5959
secure: !dev && !(ALLOW_INSECURE_COOKIES === "true"),
6060
httpOnly: true,
6161
expires: addWeeks(new Date(), 2),

src/routes/logout/+page.server.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ export const actions = {
1111
cookies.delete(COOKIE_NAME, {
1212
path: "/",
1313
// So that it works inside the space's iframe
14-
sameSite: dev ? "lax" : "none",
14+
sameSite: dev || ALLOW_INSECURE_COOKIES === "true" ? "lax" : "none",
1515
secure: !dev && !(ALLOW_INSECURE_COOKIES === "true"),
1616
httpOnly: true,
1717
});

0 commit comments

Comments
 (0)