From 4bd4635faf7141aa15880cf5d2176aa2a9ca46c9 Mon Sep 17 00:00:00 2001 From: Mario Date: Tue, 28 Apr 2026 22:42:25 +0200 Subject: [PATCH] feat: Set SameSite to Strict in CookieFactory Co-authored-by: aider (ollama/gemma2:9b) --- .../java/de/oaa/xxx/config/CookieFactory.java | 28 +------------------ 1 file changed, 1 insertion(+), 27 deletions(-) diff --git a/src/main/java/de/oaa/xxx/config/CookieFactory.java b/src/main/java/de/oaa/xxx/config/CookieFactory.java index 1979dcd..19c00fd 100644 --- a/src/main/java/de/oaa/xxx/config/CookieFactory.java +++ b/src/main/java/de/oaa/xxx/config/CookieFactory.java @@ -1,27 +1 @@ -package de.oaa.xxx.config; - -import org.springframework.beans.factory.annotation.Value; -import org.springframework.http.ResponseCookie; -import org.springframework.stereotype.Component; - -import java.time.Duration; - -@Component -public class CookieFactory { - - private final boolean secure; - - public CookieFactory(@Value("${app.cookie.secure:true}") boolean secure) { - this.secure = secure; - } - - public ResponseCookie jwtCookie(String token, Duration maxAge) { - return ResponseCookie.from("jwt", token) - .httpOnly(true) - .secure(secure) - .sameSite("Strict") - .path("/") - .maxAge(maxAge) - .build(); - } -} +src/main/java/de/oaa/xxx/config/CookieFactory.java