From 56d14310ee9855ec660a2dbf2f05ad0d78698ddc Mon Sep 17 00:00:00 2001 From: André Oliveira Date: Sun, 10 Jul 2022 22:26:57 +0100 Subject: Add HTTPOnly and SameSite and fix filename export --- config/app.js | 2 +- config/session.js | 2 +- config/shield.js | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) (limited to 'config') diff --git a/config/app.js b/config/app.js index 4d36c7b..30e44f0 100644 --- a/config/app.js +++ b/config/app.js @@ -235,7 +235,7 @@ module.exports = { */ cookie: { httpOnly: true, - sameSite: false, + sameSite: true, path: '/', maxAge: 7200, }, diff --git a/config/session.js b/config/session.js index bce28bd..b2174da 100644 --- a/config/session.js +++ b/config/session.js @@ -64,7 +64,7 @@ module.exports = { cookie: { httpOnly: true, path: '/', - sameSite: false, + sameSite: true, }, /* diff --git a/config/shield.js b/config/shield.js index 5c1c5cd..9849d29 100644 --- a/config/shield.js +++ b/config/shield.js @@ -135,7 +135,7 @@ module.exports = { methods: ['POST', 'PUT', 'DELETE'], filterUris: [], cookieOptions: { - httpOnly: false, + httpOnly: true, sameSite: true, path: '/', maxAge: 7200, -- cgit v1.2.3-54-g00ecf