fix: enfore secure for production environments

This commit is contained in:
Max Peintner
2025-05-19 14:41:57 +02:00
parent a4d703362f
commit 949581d81c

View File

@@ -31,7 +31,8 @@ async function setSessionHttpOnlyCookie<T>(
value: JSON.stringify(sessions),
httpOnly: true,
path: "/",
sameSite,
sameSite: process.env.NODE_ENV === "production" ? sameSite : "lax",
secure: process.env.NODE_ENV === "production",
});
}