create new auth files
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
import type { Cookies } from '@sveltejs/kit';
|
||||
|
||||
// The PocketBase JWT lives in a single cookie shared by:
|
||||
// - the server hooks (authRefresh -> locals.user)
|
||||
// - the client SDK (seeded from page.data.pbToken -> authenticated famStore reads/subscribe)
|
||||
// httpOnly keeps the token out of reach of browser JS/XSS; the client receives
|
||||
// the token server-side via the layout load (pbToken) and seeds pb.authStore.
|
||||
// Secure flag is set in prod so it's only sent over HTTPS.
|
||||
export const SESSION_COOKIE = 'pb_token';
|
||||
const MAX_AGE = 60 * 60 * 24; // 24h, PB token exp is the real ceiling
|
||||
|
||||
export function setSessionCookie(cookies: Cookies, token: string) {
|
||||
cookies.set(SESSION_COOKIE, token, {
|
||||
httpOnly: true,
|
||||
sameSite: 'lax',
|
||||
path: '/',
|
||||
maxAge: MAX_AGE,
|
||||
secure: import.meta.env.PROD
|
||||
});
|
||||
}
|
||||
|
||||
export function clearSessionCookie(cookies: Cookies) {
|
||||
cookies.delete(SESSION_COOKIE, { path: '/' });
|
||||
}
|
||||
Reference in New Issue
Block a user