Remove Cookie secure options

almost server is not using https, so disable it.
This commit is contained in:
Tensa
2023-02-15 07:01:51 +09:00
committed by GitHub
parent cb00faa570
commit 44e7d2ab01

View File

@@ -70,6 +70,7 @@ const { invalidCsrfTokenError, generateToken, doubleCsrfProtection } = doubleCsr
cookieOptions: { cookieOptions: {
httpOnly: true, httpOnly: true,
sameSite: "strict", sameSite: "strict",
secure: false
}, },
size: 64, size: 64,
getTokenFromRequest: (req) => req.headers["x-csrf-token"] getTokenFromRequest: (req) => req.headers["x-csrf-token"]