We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
2 parents 09349ca + 27a7254 commit 6c24ca2Copy full SHA for 6c24ca2
apps/app/src/middleware.ts
@@ -29,7 +29,13 @@ export async function middleware(request: NextRequest) {
29
}
30
31
// Cookie-only gating (auth will validate server-side on actual routes)
32
- const sessionToken = request.cookies.get('better-auth.session_token')?.value;
+ const secureCookieName = '__Secure-better-auth.session_token';
33
+ const fallbackCookieName = 'better-auth.session_token';
34
+
35
+ let sessionToken = request.cookies.get(secureCookieName)?.value;
36
+ if (!sessionToken) {
37
+ sessionToken = request.cookies.get(fallbackCookieName)?.value;
38
+ }
39
const hasToken = Boolean(sessionToken);
40
const nextUrl = request.nextUrl;
41
const requestHeaders = new Headers(request.headers);
0 commit comments