We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent e3d3f10 commit 27a7254Copy full SHA for 27a7254
apps/app/src/middleware.ts
@@ -29,7 +29,13 @@ export async function middleware(request: NextRequest) {
29
}
30
31
// Cookie-only gating (auth will validate server-side on actual routes)
32
- const sessionToken = request.cookies.get('better-auth.session_token')?.value;
+ const secureCookieName = '__Secure-better-auth.session_token';
33
+ const fallbackCookieName = 'better-auth.session_token';
34
+
35
+ let sessionToken = request.cookies.get(secureCookieName)?.value;
36
+ if (!sessionToken) {
37
+ sessionToken = request.cookies.get(fallbackCookieName)?.value;
38
+ }
39
const hasToken = Boolean(sessionToken);
40
const nextUrl = request.nextUrl;
41
const requestHeaders = new Headers(request.headers);
0 commit comments