fix: use SameSite=Lax for session cookie
Release Desktop Apps / build-linux (push) Successful in 2m59s
Release Desktop Apps / release (push) Has been cancelled
Release Desktop Apps / build-windows (push) Has been cancelled

SameSite=None requires Secure=true or modern browsers silently reject
the Set-Cookie header. Since the site is served over HTTPS via Caddy,
this was causing login to succeed (200) but the session cookie to be
dropped, making the subsequent /auth/me call fail with 401.

SameSite=Lax is the correct setting for same-origin session cookies.
This commit is contained in:
2026-07-16 14:52:13 -04:00
parent 08e5d92059
commit 9491f3a831
+2 -1
View File
@@ -17,7 +17,8 @@ func SetSessionCookie(w http.ResponseWriter, cookieName, token string, duration
Path: "/",
HttpOnly: true,
Secure: secure,
SameSite: http.SameSiteNoneMode,
SameSite: http.SameSiteLaxMode,
MaxAge: int(duration.Seconds()),
})
}