diff --git a/src/main/java/univ/yesummit/global/oauth/OAuth2SuccessHandler.java b/src/main/java/univ/yesummit/global/oauth/OAuth2SuccessHandler.java index 796e575..27bef9b 100644 --- a/src/main/java/univ/yesummit/global/oauth/OAuth2SuccessHandler.java +++ b/src/main/java/univ/yesummit/global/oauth/OAuth2SuccessHandler.java @@ -48,14 +48,14 @@ public void onAuthenticationSuccess(HttpServletRequest request, HttpServletRespo int refreshTokenMaxAge = jwtUtils.getRefreshExpiration().intValue() / 1000; Cookie accessTokenCookie = new Cookie("accessToken", accessToken); - accessTokenCookie.setHttpOnly(true); - accessTokenCookie.setSecure(true); + accessTokenCookie.setHttpOnly(true); // js 접근 불가 + accessTokenCookie.setSecure(false); accessTokenCookie.setPath("/"); accessTokenCookie.setMaxAge(accessTokenMaxAge); Cookie refreshTokenCookie = new Cookie("refreshToken", refreshToken); - refreshTokenCookie.setHttpOnly(true); - refreshTokenCookie.setSecure(true); + refreshTokenCookie.setHttpOnly(true); // js 접근 불가 + refreshTokenCookie.setSecure(false); refreshTokenCookie.setPath("/"); refreshTokenCookie.setMaxAge(refreshTokenMaxAge);