package auth import ( "net/http" "time" ) const CookieName = "session" // SetSessionCookie sets the session cookie; secure marks it for https only, // which the app cannot tell on its own behind a plain-http proxy. func SetSessionCookie(w http.ResponseWriter, token string, secure bool) { http.SetCookie(w, sessionCookie(token, int(SessionTTL/time.Second), secure)) } // ClearSessionCookie expires the cookie with the same attributes it was set // with; browsers only replace a cookie whose Secure flag matches. func ClearSessionCookie(w http.ResponseWriter, secure bool) { http.SetCookie(w, sessionCookie("", -1, secure)) } func sessionCookie(value string, maxAge int, secure bool) *http.Cookie { return &http.Cookie{ Name: CookieName, Value: value, Path: "/", HttpOnly: true, Secure: secure, SameSite: http.SameSiteLaxMode, MaxAge: maxAge, } }