Harden cookie authentication
This commit is contained in:
1 parent
a0a62c1c06
commit
31e6c0c5d2
5 files changed
+116
-17
No files matched your search
@@ -1,7 +1,13 @@
|
||||
import { deleteCookie } from "h3"
|
||||
import { REFRESH_COOKIE, SESSION_COOKIE } from "../../utils/auth"
|
||||
import {
|
||||
assertCookieRequestOrigin,
|
||||
defineAuthenticatedEventHandler,
|
||||
REFRESH_COOKIE,
|
||||
SESSION_COOKIE,
|
||||
} from "../../utils/auth"
|
||||
|
||||
export default defineEventHandler((event) => {
|
||||
export default defineAuthenticatedEventHandler((event) => {
|
||||
assertCookieRequestOrigin(event)
|
||||
deleteCookie(event, REFRESH_COOKIE, { path: "/", sameSite: "lax", secure: !import.meta.dev })
|
||||
deleteCookie(event, SESSION_COOKIE, { path: "/", sameSite: "lax", secure: !import.meta.dev })
|
||||
return { success: true }
|
||||
|
||||
Reference in new issue
Block a user