fix: update cookie settings for production and development modes
This commit is contained in:
@@ -127,8 +127,11 @@ public class AuthService {
|
|||||||
.path("/");
|
.path("/");
|
||||||
|
|
||||||
return switch (applicationMode) {
|
return switch (applicationMode) {
|
||||||
case PRODUCTION -> cookieBuilder.httpOnly(true);
|
case PRODUCTION -> cookieBuilder
|
||||||
case DEVELOPMENT -> cookieBuilder.sameSite("NONE");
|
.httpOnly(true)
|
||||||
|
.sameSite("LAX");
|
||||||
|
case DEVELOPMENT -> cookieBuilder
|
||||||
|
.sameSite("NONE");
|
||||||
case null -> cookieBuilder;
|
case null -> cookieBuilder;
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user