Skip to content

fix(auth): set token cookies Secure only over HTTPS - #2

Open
nossila wants to merge 1 commit into
merge/baseapp-filesfrom
fix/secure-token-cookies-over-https
Open

nossila wants to merge 1 commit into
merge/baseapp-filesfrom
fix/secure-token-cookies-over-https

Conversation

@nossila

@nossila nossila commented Oct 4, 2026

Copy link
Copy Markdown
Member

Summary

Login on a production build served over plain HTTP never kept the user signed in. Stacked on #1 (merge/baseapp-files), the branch whatplant pins.

  • Cause: useLogin and refreshAccessToken set the access and refresh token cookies with secure: process.env.NODE_ENV === 'production'. On a next start build served over http:// (a LAN test server or a staging host without TLS), browsers drop Secure cookies set from HTTP pages, except on localhost.
  • Result: the token request succeeded, but no Authorization / Refresh cookie was stored, so /v1/users/me answered 401 Authentication credentials were not provided.
  • Fix: new shouldUseSecureCookies() in @baseapp-frontend/utils.
    • In the browser it follows window.location.protocol.
    • Elsewhere (SSR, native) it keeps the NODE_ENV rule.
    • useLogin and refreshAccessToken use it.
    • HTTPS deployments keep Secure cookies.
  • Changeset: patch for @baseapp-frontend/utils and @baseapp-frontend/authentication.
  • Projects that set token cookies in their own middleware.ts with the same NODE_ENV rule should switch to the request's scheme (X-Forwarded-Proto behind a proxy). The whatplant frontend does this in its own PR.

Worth upstreaming to silverlogic/baseapp-frontend: the bug is in the template's defaults.

Test plan

  • vitest: functions/token 29 passed (new shouldUseSecureCookies tests), useLogin 3 passed.
  • On a whatplant production build served at http://10.244.99.39:3001:
    • before: after login only Language and CurrentProfile cookies exist;
    • after: Authorization and Refresh are stored, and the account menu and signed-in navigation show.

🤖 Generated with Claude Code

https://claude.ai/code/session_019P1oyApi4BLS8iLfMEGm8b

Login on a production build served over plain HTTP (e.g. a LAN test server) never stored the
access and refresh tokens: they were marked Secure because NODE_ENV is "production", and
browsers drop Secure cookies set from HTTP pages, so /users/me answered 401.

shouldUseSecureCookies() follows the page's protocol in the browser and keeps the NODE_ENV
rule elsewhere; useLogin and refreshAccessToken use it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019P1oyApi4BLS8iLfMEGm8b
@nossila
nossila requested a review from matheusysd as a code owner October 4, 2026 17:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant