fix: oturum çerezini x-forwarded-proto'ya göre secure işaretle
NODE_ENV=production'da cookie hep secure:true oluyordu, ama panel şu an SSL'siz sslip.io preview domain'inde (http://) çalışıyor — tarayıcı Secure cookie'yi HTTP origin'de hiç saklamıyor. Giriş "başarılı" gibi görünüp anında /login'e geri dönülüyordu. Artık gerçek istek protokolüne (Traefik'in x-forwarded-proto header'ı) bakılıyor. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,6 +1,6 @@
|
|||||||
"use server";
|
"use server";
|
||||||
|
|
||||||
import { cookies } from "next/headers";
|
import { cookies, headers } from "next/headers";
|
||||||
import { redirect } from "next/navigation";
|
import { redirect } from "next/navigation";
|
||||||
import bcrypt from "bcryptjs";
|
import bcrypt from "bcryptjs";
|
||||||
import { prisma } from "@streamclipper/db";
|
import { prisma } from "@streamclipper/db";
|
||||||
@@ -11,9 +11,16 @@ const SESSION_MAX_AGE_SEC = 60 * 60 * 24 * 30;
|
|||||||
async function setSessionCookie(userId: string, username: string) {
|
async function setSessionCookie(userId: string, username: string) {
|
||||||
const token = await createSessionToken({ sub: userId, username });
|
const token = await createSessionToken({ sub: userId, username });
|
||||||
const jar = await cookies();
|
const jar = await cookies();
|
||||||
|
// NODE_ENV alone isn't a reliable signal for this — the panel is often
|
||||||
|
// served over plain HTTP (e.g. Coolify's auto-generated sslip.io preview
|
||||||
|
// domain has no TLS). A `Secure` cookie set on an HTTP origin is silently
|
||||||
|
// dropped by the browser, which made every login look successful for an
|
||||||
|
// instant and then immediately bounce back to /login. Check the actual
|
||||||
|
// request scheme instead (Traefik/Coolify sets x-forwarded-proto).
|
||||||
|
const proto = (await headers()).get("x-forwarded-proto");
|
||||||
jar.set(SESSION_COOKIE_NAME, token, {
|
jar.set(SESSION_COOKIE_NAME, token, {
|
||||||
httpOnly: true,
|
httpOnly: true,
|
||||||
secure: process.env.NODE_ENV === "production",
|
secure: proto === "https",
|
||||||
sameSite: "lax",
|
sameSite: "lax",
|
||||||
path: "/",
|
path: "/",
|
||||||
maxAge: SESSION_MAX_AGE_SEC,
|
maxAge: SESSION_MAX_AGE_SEC,
|
||||||
|
|||||||
Reference in New Issue
Block a user