fix(19): BL-02 match Secure attribute on logout cookie deletion to issue-time logic
This commit is contained in:
@@ -98,9 +98,13 @@ export function clearLocalSessionCookie(c: Context): void {
|
|||||||
deleteCookie(c, COOKIE_NAME, {
|
deleteCookie(c, COOKIE_NAME, {
|
||||||
path: '/',
|
path: '/',
|
||||||
httpOnly: true,
|
httpOnly: true,
|
||||||
// Use secure:true for delete (browsers only accept the attribute in matching context)
|
// BL-02: mirror the issue-time `secure` logic. issueLocalSessionCookie sets
|
||||||
// In practice this is safe because logout should happen over HTTPS in production.
|
// secure:false over plain HTTP (non-production), and a browser will REJECT a
|
||||||
secure: true,
|
// Secure delete-cookie sent over HTTP — so a hard-coded secure:true left the
|
||||||
|
// local-session cookie uncleared on every non-HTTPS deployment (local dev and any
|
||||||
|
// HTTP-only self-host), leaving the user "logged in" after logout. Match the
|
||||||
|
// context so the deletion cookie is accepted.
|
||||||
|
secure: process.env.NODE_ENV === 'production',
|
||||||
sameSite: 'Lax',
|
sameSite: 'Lax',
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user