From ac768ed0dbc374883e9899b4abe924c3084b3926 Mon Sep 17 00:00:00 2001 From: jhodgkin Date: Sun, 12 Jul 2026 20:21:52 -0600 Subject: [PATCH] fix: decouple session cookie 'secure' flag from NODE_ENV Cookie was silently never set because NODE_ENV=production forced secure=true while the app is served over plain HTTP on the LAN (TLS terminates at a reverse proxy later, not here). Add explicit COOKIE_SECURE env var, default false. Co-Authored-By: Claude Sonnet 5 --- .env.example | 5 +++++ apps/api/src/config/index.ts | 4 ++++ apps/api/src/index.ts | 2 +- 3 files changed, 10 insertions(+), 1 deletion(-) diff --git a/.env.example b/.env.example index e7887a1..2c8913f 100644 --- a/.env.example +++ b/.env.example @@ -16,6 +16,11 @@ ADMIN_PASSWORD= # local | oidc (oidc not implemented yet, see issue #12) AUTH_MODE=local +# Set to true only once a TLS-terminating reverse proxy sits in front (see +# issue #13). Leave false for plain-HTTP LAN access, otherwise the session +# cookie won't be set at all. +COOKIE_SECURE=false + PORT=3000 POLL_INTERVAL_SECONDS=30 SNAPSHOT_RETENTION_HOURS=24 diff --git a/apps/api/src/config/index.ts b/apps/api/src/config/index.ts index 4319bb4..15f9e05 100644 --- a/apps/api/src/config/index.ts +++ b/apps/api/src/config/index.ts @@ -15,6 +15,9 @@ export interface AppConfig { snapshotRetentionHours: number; authMode: "local" | "oidc"; sessionSecret: string; + // Only set once a TLS-terminating reverse proxy sits in front (see issue #13) — + // browsers silently drop `secure` cookies over plain HTTP. + cookieSecure: boolean; adminUsername: string; adminPassword: string | undefined; proxmox: { @@ -42,6 +45,7 @@ export function loadConfig(hostsConfigPath: string): AppConfig { snapshotRetentionHours: Number(process.env.SNAPSHOT_RETENTION_HOURS ?? 24), authMode: (process.env.AUTH_MODE as "local" | "oidc") ?? "local", sessionSecret: required("SESSION_SECRET"), + cookieSecure: process.env.COOKIE_SECURE === "true", adminUsername: process.env.ADMIN_USERNAME ?? "admin", adminPassword: process.env.ADMIN_PASSWORD, proxmox: { diff --git a/apps/api/src/index.ts b/apps/api/src/index.ts index ee68fbd..b12dc33 100644 --- a/apps/api/src/index.ts +++ b/apps/api/src/index.ts @@ -46,7 +46,7 @@ async function main() { await app.register(fastifyCookie); await app.register(fastifySession, { secret: cfg.sessionSecret, - cookie: { secure: process.env.NODE_ENV === "production", maxAge: 1000 * 60 * 60 * 12 }, + cookie: { secure: cfg.cookieSecure, maxAge: 1000 * 60 * 60 * 12 }, }); registerAuthRoutes(app, db);