【问题标题】:How to set sameSite and Secure attributes in a cookie with express?如何使用 express 在 cookie 中设置 sameSite 和 Secure 属性?
【发布时间】:2020-09-24 02:47:41
【问题描述】:

我有这个创建 cookie 的服务器 API 代码,我需要设置 samesite 和 Secure 属性以消除警告,所以我像在 post 中一样添加了它们,但我现在收到错误

请求失败,状态码为 500

app.post('/api/login', (req, res) => {
    User.findOne({'email': req.body.email}, (err, user) => {
        if (!user) return res.json({isAuth: false, message: 'Auth failed no email'});

        user.comparePassword(req.body.password, (err, isMatch) => {
            if (!isMatch) return res.json({isAuth: false, message: 'wrong password'});

            user.generateToken((err, User) => {
                if (err) return res.status(400).send(err);
                res.cookie('auth', user.token, {samesite:none, secure:true}).send({isAuth: true, id: user._id, email: user.email });
            })
        })
    })
})

这是设置相同站点和安全属性的正确方法吗?我该如何解决这个问题?

没有{samesite:none, secure:true},API 工作正常。

【问题讨论】:

    标签: node.js express


    【解决方案1】:

    使用sameSite:'none' 而不是samesite:none

    【讨论】:

      猜你喜欢
      • 2021-01-04
      • 2020-02-09
      • 2020-11-22
      • 1970-01-01
      • 2020-03-30
      • 2019-06-03
      • 1970-01-01
      • 2020-07-04
      • 1970-01-01
      相关资源
      最近更新 更多