fix: use SameSite=Lax for session cookie

SameSite=None requires Secure=true or modern browsers silently reject
the Set-Cookie header. Since the site is served over HTTPS via Caddy,
this was causing login to succeed (200) but the session cookie to be
dropped, making the subsequent /auth/me call fail with 401.

SameSite=Lax is the correct setting for same-origin session cookies.
This commit is contained in:
2026-07-16 14:52:13 -04:00
parent bda4c9d73d
commit a8cb5c5933
+2 -1
View File
@@ -17,7 +17,8 @@ func SetSessionCookie(w http.ResponseWriter, cookieName, token string, duration
Path: "/",
HttpOnly: true,
Secure: secure,
SameSite: http.SameSiteNoneMode,
SameSite: http.SameSiteLaxMode,
MaxAge: int(duration.Seconds()),
})
}