Skip to content

Commit 915eef6

Browse files
committed
fix: updated cookies to use SameSite=Lax
1 parent 29f3106 commit 915eef6

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

src/runtime/server/utils/security.ts

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -70,11 +70,11 @@ export const checks = {
7070
console.log('pkceChallenge', pkceChallenge)
7171
res['code_challenge'] = pkceChallenge
7272
res['code_challenge_method'] = 'S256'
73-
setCookie(event, 'nuxt-auth-util-verifier', pkceVerifier, { maxAge: 60 * 15, secure: true, httpOnly: true })
73+
setCookie(event, 'nuxt-auth-util-verifier', pkceVerifier, { maxAge: 60 * 15, secure: true, httpOnly: true, sameSite: 'lax' })
7474
}
7575
if (checks?.includes('state')) {
7676
res['state'] = generateState()
77-
setCookie(event, 'nuxt-auth-util-state', res['state'], { maxAge: 60 * 15, secure: true, httpOnly: true })
77+
setCookie(event, 'nuxt-auth-util-state', res['state'], { maxAge: 60 * 15, secure: true, httpOnly: true, sameSite: 'lax' })
7878
}
7979
return res
8080
},

0 commit comments

Comments
 (0)