From 1410dc84f61b2d702a5c77d0fc36b1a0ae2d678c Mon Sep 17 00:00:00 2001 From: suricatingss Date: Sun, 18 Jan 2026 22:06:33 +0000 Subject: [PATCH] cookie now supports http and https --- server/routes/login.post.ts | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/server/routes/login.post.ts b/server/routes/login.post.ts index 6b9ee83..43baa25 100644 --- a/server/routes/login.post.ts +++ b/server/routes/login.post.ts @@ -3,6 +3,9 @@ export default defineEventHandler(async (event) => { const body = await readBody(event) + const is_https = await getRequestProtocol(event) == "https" + //console.log(is_https) + if ( !body.email || !body.password ) throw createError({ statusCode: 400, message: "Bad form. Use e-mail and password" }) //console.log(body) @@ -32,6 +35,11 @@ export default defineEventHandler(async (event) => { secure: { user_id: body.id } + }, { + cookie: { + secure: is_https, + sameSite: is_https ? 'none' : 'lax' + } }) console.log(await getUserSession(event))