Update secure cookie setting to conditionally use HTTPS protocol in authentication flows
This commit is contained in:
@@ -47,7 +47,7 @@ export const authHook: Handle = async ({ event, resolve }) => {
|
||||
path: '/',
|
||||
httpOnly: true,
|
||||
sameSite: 'lax',
|
||||
secure: true,
|
||||
secure: event.url.protocol === 'https:',
|
||||
expires: expiryDate
|
||||
});
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user