This commit is contained in:
Evert Prants 2019-06-16 13:12:40 +03:00
parent 306f77aafe
commit 85578611a5
Signed by: evert
GPG Key ID: 1688DA83D222D0B5
2 changed files with 5 additions and 7 deletions

View File

@ -33,6 +33,8 @@ if (dev) {
app.use(morgan('dev')) app.use(morgan('dev'))
} }
app.set('trust proxy', 1)
const router = express.Router() const router = express.Router()
const sortfields = ['id', 'track', 'artist', 'title', 'album', 'year', 'file'] const sortfields = ['id', 'track', 'artist', 'title', 'album', 'year', 'file']
@ -46,7 +48,7 @@ app.use(session({
resave: false, resave: false,
saveUninitialized: true, saveUninitialized: true,
cookie: { cookie: {
secure: process.env.NODE_ENV !== 'development', secure: !dev,
maxAge: 2678400000 // 1 month maxAge: 2678400000 // 1 month
} }
})) }))

View File

@ -94,12 +94,8 @@ export function user (dbPromise, oauth, registrations) {
}) })
router.get('/login/oauth', async (req, res) => { router.get('/login/oauth', async (req, res) => {
let state let state = crypto.randomBytes(16).toString('hex')
if (req.session && req.session.oauthState) { req.session.oauthState = state
state = req.session.oauthState
} else {
req.session.oauthState = crypto.randomBytes(16).toString('hex')
}
return res.redirect(oauth2.getAuthorizeUrl({ return res.redirect(oauth2.getAuthorizeUrl({
'redirect_uri': oauth.redirectUri, 'redirect_uri': oauth.redirectUri,