Session cookie had no maxAge, so browsers dropped it on their own
schedule and the store's default 1-day TTL expired idle sessions —
logging people out unpredictably. Set a 400-day maxAge (the browser
cap) with rolling:true so the window slides forward on each visit,
and gate Secure cookies + trust-proxy behind NODE_ENV=production so
local http dev still works. Deploy script now sets NODE_ENV too.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Changes already present in the working tree at the time of the versioning
commit, committed here so nothing is left dangling:
- index.js: template PUT preserves the untouched field (?? existing) and the
preview handler tolerates a null/empty test_object
- update-deployed.sh: detect and restart a pm2-managed app process, and don't
hard-fail when no bare Node process is found
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>