fix: oturum çerezini x-forwarded-proto'ya göre secure işaretle

NODE_ENV=production'da cookie hep secure:true oluyordu, ama panel
şu an SSL'siz sslip.io preview domain'inde (http://) çalışıyor —
tarayıcı Secure cookie'yi HTTP origin'de hiç saklamıyor. Giriş
"başarılı" gibi görünüp anında /login'e geri dönülüyordu. Artık
gerçek istek protokolüne (Traefik'in x-forwarded-proto header'ı)
bakılıyor.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-01 12:10:11 +03:00
co-authored by Claude Sonnet 5
parent fb8485d638
commit 775633bfd0
+9 -2
View File
@@ -1,6 +1,6 @@
"use server";
import { cookies } from "next/headers";
import { cookies, headers } from "next/headers";
import { redirect } from "next/navigation";
import bcrypt from "bcryptjs";
import { prisma } from "@streamclipper/db";
@@ -11,9 +11,16 @@ const SESSION_MAX_AGE_SEC = 60 * 60 * 24 * 30;
async function setSessionCookie(userId: string, username: string) {
const token = await createSessionToken({ sub: userId, username });
const jar = await cookies();
// NODE_ENV alone isn't a reliable signal for this — the panel is often
// served over plain HTTP (e.g. Coolify's auto-generated sslip.io preview
// domain has no TLS). A `Secure` cookie set on an HTTP origin is silently
// dropped by the browser, which made every login look successful for an
// instant and then immediately bounce back to /login. Check the actual
// request scheme instead (Traefik/Coolify sets x-forwarded-proto).
const proto = (await headers()).get("x-forwarded-proto");
jar.set(SESSION_COOKIE_NAME, token, {
httpOnly: true,
secure: process.env.NODE_ENV === "production",
secure: proto === "https",
sameSite: "lax",
path: "/",
maxAge: SESSION_MAX_AGE_SEC,