Files
Deep-Package-Inspection/docs/log/2026-07-24-0910-session-cookie-security.md
T

940 B

Iteration Log - 2026-07-24 09:10 - Session Cookie Security

Request: Configure the authentication token cookie to expire immediately upon browser closure so that users are forced to log in upon reopening the browser.

Affected files:

  • backend/routes/auth/helpers.js

Solution

  1. Analysis:

    • The auth token cookie was configured with maxAge: 24 * 60 * 60 * 1000 (24 hours).
    • This made it a persistent cookie stored on disk, so reopening the browser sent the cookie and bypassed the login screen.
  2. Implementation:

    • Removed the maxAge option from res.cookie('token', ...) in setCookieToken inside backend/routes/auth/helpers.js.
    • The browser now stores the cookie in memory only and discards it when closed (standard session cookie behavior).
  3. Deployment:

    • Deployed successfully using node scripts/deploy-sftp.js.
    • PM2 backend service reloaded on the production server.