longer cookie
This commit is contained in:
@@ -68,11 +68,11 @@ export default class AuthHandler {
|
|||||||
const token = jwt.sign(payload, secret, options);
|
const token = jwt.sign(payload, secret, options);
|
||||||
|
|
||||||
res.cookie("auth_token", token, {
|
res.cookie("auth_token", token, {
|
||||||
httpOnly: true, // cannot be accessed by JS
|
httpOnly: true, // cannot be accessed by JS
|
||||||
secure: process.env.ENV === "production", // only over HTTPS
|
secure: process.env.ENV === "production", // only over HTTPS
|
||||||
sameSite: "lax", // like SameSiteLaxMode
|
sameSite: "lax", // like SameSiteLaxMode
|
||||||
maxAge: 2 * 60 * 60 * 1000, // 2 hours in milliseconds
|
maxAge: 60 * 24 * 60 * 60 * 1000, // 60 days
|
||||||
path: "/", // available on entire site
|
path: "/", // available on entire site
|
||||||
domain: process.env.ENV === "production" ? "." + process.env.BASE_URL : undefined
|
domain: process.env.ENV === "production" ? "." + process.env.BASE_URL : undefined
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user