diff --git a/server/utils/signed-cookie.ts b/server/utils/signed-cookie.ts index b7c4129..88b9687 100644 --- a/server/utils/signed-cookie.ts +++ b/server/utils/signed-cookie.ts @@ -25,7 +25,7 @@ export async function setSignedCookie(event: H3Event, name: string, value: strin const secret = await useCookieSecret(event); const signature = await crypto.subtle.sign("HMAC", secret, Buffer.from(`${name}=${value}`)); const cookie = `${value}.${Buffer.from(signature).toString("base64url")}` - setCookie(event, name, cookie, { httpOnly: true, secure: true, sameSite: true, maxAge }); + setCookie(event, name, cookie, { httpOnly: true, secure: true, sameSite: "lax", maxAge }); } export async function getSignedCookie(event: H3Event, name: string) {