fix: decouple session cookie 'secure' flag from NODE_ENV
CI / web (push) Successful in 16s
CI / api (push) Successful in 17s

Cookie was silently never set because NODE_ENV=production forced
secure=true while the app is served over plain HTTP on the LAN (TLS
terminates at a reverse proxy later, not here). Add explicit
COOKIE_SECURE env var, default false.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-12 20:21:52 -06:00
parent a075488f4b
commit ac768ed0db
3 changed files with 10 additions and 1 deletions
+1 -1
View File
@@ -46,7 +46,7 @@ async function main() {
await app.register(fastifyCookie);
await app.register(fastifySession, {
secret: cfg.sessionSecret,
cookie: { secure: process.env.NODE_ENV === "production", maxAge: 1000 * 60 * 60 * 12 },
cookie: { secure: cfg.cookieSecure, maxAge: 1000 * 60 * 60 * 12 },
});
registerAuthRoutes(app, db);