940 B
940 B
Iteration Log - 2026-07-24 09:10 - Session Cookie Security
Request: Configure the authentication token cookie to expire immediately upon browser closure so that users are forced to log in upon reopening the browser.
Affected files:
backend/routes/auth/helpers.js
Solution
-
Analysis:
- The auth token cookie was configured with
maxAge: 24 * 60 * 60 * 1000(24 hours). - This made it a persistent cookie stored on disk, so reopening the browser sent the cookie and bypassed the login screen.
- The auth token cookie was configured with
-
Implementation:
- Removed the
maxAgeoption fromres.cookie('token', ...)insetCookieTokeninsidebackend/routes/auth/helpers.js. - The browser now stores the cookie in memory only and discards it when closed (standard session cookie behavior).
- Removed the
-
Deployment:
- Deployed successfully using
node scripts/deploy-sftp.js. - PM2 backend service reloaded on the production server.
- Deployed successfully using