Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Express-session cookie not saving in browser

I've been researching this for hours now. What could be the reason why the cookies are not being saved in the browser? I'm using express-session. Below are the pieces of code I'm using.

const app = express();

// CORS config
app.use(cors({
  origin: process.env.API_URL,
  credentials: true,
  optionsSuccessStatus: 200
}));

app.use(cookieParser());

// Where the sessions are stored
const MongoDBStore = new MongoDBSession({
  uri: process.env.MEDIRECORDS_URI,
  collection: "sessions"
})

app.set("trust proxy", 1);

const oneDay = 1000 * 60 * 60 * 24;

app.use(session({
  name: "irmp_session",
  secret: process.env.AWS_SESSION_KEY,
  resave: false,
  saveUninitialized: false,
  maxAge: 7200000, // 2 hrs validity
  store: MongoDBStore,
   cookie: {
    path: '/',
    sameSite: false,
    secure: false,
    maxAge: oneDay
  }
}))

When I try to login using the frontend, the login is successful, the session is stored in the database. However, when I check the cookie storage, it is empty.

like image 730
orangesheep Avatar asked Aug 06 '26 06:08

orangesheep


1 Answers

After spending hours of researching, I learned that this is due to Chrome's cookie updates. Here is what the update is all about.

As the link states, for a cookie to be saved in Chrome and if it is really needed to set the sameSite to none, developers should set the secure option to be true. Default value of sameSite if not set is lax.

Hope this helps anyone who might encounter the problem.

like image 110
orangesheep Avatar answered Aug 08 '26 22:08

orangesheep