Merge pull request #50 from 10sa/patch-3

Remove Cookie secure options
This commit is contained in:
Borov666
2023-02-15 02:04:31 +04:00
committed by GitHub

View File

@@ -70,6 +70,7 @@ const { invalidCsrfTokenError, generateToken, doubleCsrfProtection } = doubleCsr
cookieOptions: {
httpOnly: true,
sameSite: "strict",
secure: false
},
size: 64,
getTokenFromRequest: (req) => req.headers["x-csrf-token"]