fix(auth): detect HTTPS via X-Forwarded-Proto for SameSite=None cookies, fix AuthGuard null overwrite

- Cookie SameSite now dynamic: None;Secure when behind HTTPS proxy, Lax otherwise
- AuthGuard useEffect no longer overwrites Zustand store with null from background refetch
- AuthInitializer: add staleTime 30s

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
MythEclipse
2026-06-15 18:17:26 +07:00
co-authored by Claude
parent 22307d44de
commit 51a4cb9ed2
4 changed files with 33 additions and 14 deletions
+16 -4
View File
@@ -28,14 +28,26 @@ function hashToken(token: string) {
return createHash('sha256').update(`${env.sessionSecret}:${token}`).digest('hex');
}
export function createSessionCookie(token: string) {
function isSecureRequest(headers?: { get(name: string): string | null }) {
if (env.secureCookies) return true;
// Detect HTTPS behind proxy (X-Forwarded-Proto)
const proto = headers?.get('x-forwarded-proto');
if (proto === 'https') return true;
return false;
}
function buildSameSite(headers?: { get(name: string): string | null }) {
return isSecureRequest(headers) ? 'SameSite=None; Secure' : 'SameSite=Lax';
}
export function createSessionCookie(token: string, headers?: { get(name: string): string | null }) {
const maxAge = 60 * 60 * 24 * 30;
const sameSite = env.secureCookies ? 'SameSite=None; Secure' : 'SameSite=Lax';
const sameSite = buildSameSite(headers);
return `${sessionCookieName}=${token}; HttpOnly; Path=/; ${sameSite}; Max-Age=${maxAge}`;
}
export function clearSessionCookie() {
const sameSite = env.secureCookies ? 'SameSite=None; Secure' : 'SameSite=Lax';
export function clearSessionCookie(headers?: { get(name: string): string | null }) {
const sameSite = buildSameSite(headers);
return `${sessionCookieName}=; HttpOnly; Path=/; ${sameSite}; Max-Age=0`;
}