Harden cookie authentication

This commit is contained in:
lucast committed 2026-09-29 15:57:07 +02:00
1 parent a0a62c1c06
commit 31e6c0c5d2
5 files changed
+116 -17

No files matched your search

+8 -2
View File
@@ -1,7 +1,13 @@
import { deleteCookie } from "h3"
import { REFRESH_COOKIE, SESSION_COOKIE } from "../../utils/auth"
import {
assertCookieRequestOrigin,
defineAuthenticatedEventHandler,
REFRESH_COOKIE,
SESSION_COOKIE,
} from "../../utils/auth"
export default defineEventHandler((event) => {
export default defineAuthenticatedEventHandler((event) => {
assertCookieRequestOrigin(event)
deleteCookie(event, REFRESH_COOKIE, { path: "/", sameSite: "lax", secure: !import.meta.dev })
deleteCookie(event, SESSION_COOKIE, { path: "/", sameSite: "lax", secure: !import.meta.dev })
return { success: true }