diff --git a/core/auth.js b/core/auth.js index ccaf1024..6ff9b61a 100644 --- a/core/auth.js +++ b/core/auth.js @@ -170,7 +170,7 @@ function handler(request, response) { } } - let cookie = `session=${session}; path=/; Max-Age=${kRefreshInterval}; Secure; SameSite=Strict`; + let cookie = `session=${session}; path=/; Max-Age=${kRefreshInterval}; ${request.client.tls ? 'Secure; ' : ''}SameSite=Strict`; let entry = readSession(session); if (entry && formData.return) { response.writeHead(303, {"Location": formData.return, "Set-Cookie": cookie}); @@ -224,7 +224,7 @@ function handler(request, response) { }); } } else if (request.uri == "/login/logout") { - response.writeHead(303, {"Set-Cookie": "session=; path=/; Secure; SameSite=Strict; expires=Thu, 01 Jan 1970 00:00:00 GMT", "Location": "/login" + (request.query ? "?" + request.query : "")}); + response.writeHead(303, {"Set-Cookie": `session=; path=/; ${request.client.tls ? 'Secure; ' : ''}SameSite=Strict; expires=Thu, 01 Jan 1970 00:00:00 GMT`, "Location": "/login" + (request.query ? "?" + request.query : "")}); response.end(); } else { response.writeHead(200, {"Content-Type": "text/plain; charset=utf-8", "Connection": "close"});