Set auth cookie to httpOnly true for security

This commit is contained in:
Ryderjj89
2025-10-01 17:48:49 -04:00
parent 2dee4e8bb1
commit d8c8c739fa

View File

@@ -22,7 +22,7 @@ export default defineEventHandler(async (event) => {
const token = await createJWT(user)
setCookie(event, 'auth_token', token, {
httpOnly: false,
httpOnly: true,
secure: process.env.NODE_ENV === 'production',
sameSite: 'lax',
maxAge: 7 * 24 * 60 * 60 // 7 days