Persistent login cookie: fix random iOS/PWA logouts

Session cookie had no maxAge, so browsers dropped it on their own
schedule and the store's default 1-day TTL expired idle sessions —
logging people out unpredictably. Set a 400-day maxAge (the browser
cap) with rolling:true so the window slides forward on each visit,
and gate Secure cookies + trust-proxy behind NODE_ENV=production so
local http dev still works. Deploy script now sets NODE_ENV too.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Your Name 2026-08-22 11:14:18 -04:00
parent 5d7bcddcd1
commit 3a7031e462
2 changed files with 34 additions and 1 deletions

View file

@ -106,6 +106,22 @@ else
echo "SESSION_SECRET already present in $APP_DIR/.env"
fi
# Production runs behind HTTPS; NODE_ENV=production flips on Secure cookies and
# trust-proxy in index.js. Set it idempotently so every deploy guarantees it.
if ! grep -Eq '^NODE_ENV=production$' .env; then
if grep -Eq '^NODE_ENV=' .env; then
ENV_TMP="$(mktemp)"
awk '/^NODE_ENV=/ { print "NODE_ENV=production"; next } { print }' .env >"$ENV_TMP"
cat "$ENV_TMP" >.env
rm -f "$ENV_TMP"
else
printf '\nNODE_ENV=production\n' >>.env
fi
echo "Set NODE_ENV=production in $APP_DIR/.env"
else
echo "NODE_ENV=production already present in $APP_DIR/.env"
fi
PM2_TARGET=""
if command -v pm2 >/dev/null 2>&1; then
PM2_TARGET="$(pm2 jlist 2>/dev/null | APP_DIR="$APP_DIR" node -e '