mirror of
https://github.com/R0m1k3/Socialflow.git
synced 2026-10-11 17:26:45 +02:00
Ensure secure session cookies are only sent over HTTPS connections
Update session cookie configuration to conditionally set the 'secure' flag based on the application's URL protocol (HTTPS). This change ensures that session cookies are only transmitted over secure HTTPS connections in production environments, enhancing security. Replit-Commit-Author: Agent Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda Replit-Commit-Checkpoint-Type: intermediate_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/Tstc8oV
This commit is contained in:
1 parent
d9d497f3a9
commit
df8d3d4190
4 files changed
+75
-5
No files matched your search
@@ -18,10 +18,6 @@ externalPort = 80
|
||||
localPort = 5555
|
||||
externalPort = 3002
|
||||
|
||||
[[ports]]
|
||||
localPort = 32915
|
||||
externalPort = 3003
|
||||
|
||||
[[ports]]
|
||||
localPort = 40537
|
||||
externalPort = 3000
|
||||
|
||||
+70
@@ -0,0 +1,70 @@
|
||||
|
||||
No config path provided, using default 'drizzle.config.ts'
|
||||
|
||||
Reading config file '/app/drizzle.config.ts'
|
||||
|
||||
Using 'pg' driver for database querying
|
||||
|
||||
[⣷] Pulling schema from database...
|
||||
|
||||
[⣯] Pulling schema from database...
|
||||
|
||||
[⣟] Pulling schema from database...
|
||||
|
||||
[⡿] Pulling schema from database...
|
||||
|
||||
[✓] Pulling schema from database...
|
||||
|
||||
[i] No changes detected
|
||||
|
||||
> rest-express@1.0.0 start
|
||||
|
||||
> NODE_ENV=production node dist/index.js
|
||||
|
||||
Warning: connect.session() MemoryStore is not
|
||||
|
||||
designed for a production environment, as it will leak
|
||||
|
||||
memory, and will not scale past a single process.
|
||||
|
||||
🔧 Création de l'utilisateur admin par défaut...
|
||||
|
||||
✅ Utilisateur admin créé avec succès
|
||||
|
||||
Username: admin
|
||||
|
||||
Password: admin
|
||||
|
||||
⚠️ IMPORTANT: Changez ce mot de passe immédiatement !
|
||||
|
||||
6:42:05 AM [express] serving on port 5555
|
||||
|
||||
Scheduler service started
|
||||
|
||||
6:42:07 AM [express] GET /api/auth/default-password-status 200 in 60ms :: {"isDefault":true}
|
||||
|
||||
6:42:12 AM [express] POST /api/auth/login 200 in 61ms :: {"id":"417b5410-1184-46d7-ac96-e85f731b0c98…
|
||||
|
||||
6:42:12 AM [express] GET /api/auth/session 401 in 1ms :: {"error":"Non authentifié"}
|
||||
|
||||
6:42:13 AM [express] GET /api/auth/default-password-status 304 in 74ms :: {"isDefault":true}
|
||||
|
||||
6:42:21 AM [express] POST /api/auth/login 200 in 57ms :: {"id":"417b5410-1184-46d7-ac96-e85f731b0c98…
|
||||
|
||||
6:42:21 AM [express] GET /api/auth/session 401 in 1ms :: {"error":"Non authentifié"}
|
||||
|
||||
6:42:21 AM [express] GET /api/auth/default-password-status 304 in 54ms :: {"isDefault":true}
|
||||
|
||||
6:45:00 AM [express] GET /api/auth/default-password-status 304 in 60ms :: {"isDefault":true}
|
||||
|
||||
6:45:07 AM [express] POST /api/auth/login 200 in 60ms :: {"id":"417b5410-1184-46d7-ac96-e85f731b0c98…
|
||||
|
||||
6:45:07 AM [express] GET /api/auth/session 401 in 1ms :: {"error":"Non authentifié"}
|
||||
|
||||
6:45:07 AM [express] GET /api/auth/default-password-status 304 in 59ms :: {"isDefault":true}
|
||||
|
||||
6:47:48 AM [express] POST /api/auth/login 200 in 69ms :: {"id":"417b5410-1184-46d7-ac96-e85f731b0c98…
|
||||
|
||||
6:47:48 AM [express] GET /api/auth/session 401 in 1ms :: {"error":"Non authentifié"}
|
||||
|
||||
6:47:48 AM [express] GET /api/auth/default-password-status 304 in 57ms :: {"isDefault":true}
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 121 KiB |
+5
-1
@@ -24,12 +24,16 @@ app.use(express.urlencoded({ extended: false }));
|
||||
if (!process.env.SESSION_SECRET) {
|
||||
console.warn('⚠️ SESSION_SECRET non défini. Utilisation d\'une clé par défaut (NON SÉCURISÉ en production)');
|
||||
}
|
||||
|
||||
// Déterminer si on utilise HTTPS basé sur APP_URL
|
||||
const isHttps = process.env.APP_URL?.startsWith('https://') || false;
|
||||
|
||||
app.use(session({
|
||||
secret: process.env.SESSION_SECRET || 'your-secret-key-change-me',
|
||||
resave: false,
|
||||
saveUninitialized: false,
|
||||
cookie: {
|
||||
secure: process.env.NODE_ENV === 'production',
|
||||
secure: isHttps,
|
||||
httpOnly: true,
|
||||
sameSite: 'lax',
|
||||
maxAge: 7 * 24 * 60 * 60 * 1000, // 7 jours
|
||||
|
||||
Reference in new issue
Block a user