From d47ee88291d2bc7a1f78d16723ca65ee3e0282bf Mon Sep 17 00:00:00 2001 From: hhvrc Date: Thu, 19 Dec 2024 20:04:36 +0100 Subject: [PATCH] Unify CookieOptions config for AuthUtils --- Common/Utils/AuthUtils.cs | 22 ++++++++++------------ 1 file changed, 10 insertions(+), 12 deletions(-) diff --git a/Common/Utils/AuthUtils.cs b/Common/Utils/AuthUtils.cs index 5086ee6..adb89d8 100644 --- a/Common/Utils/AuthUtils.cs +++ b/Common/Utils/AuthUtils.cs @@ -15,28 +15,26 @@ public static class AuthUtils "Device-Token" ]; - public static void SetSessionKeyCookie(this HttpContext context, string sessionKey, string domain) + private static CookieOptions GetCookieOptions(string domain, TimeSpan lifetime) { - context.Response.Cookies.Append(AuthConstants.UserSessionCookieName, sessionKey, new CookieOptions + return new CookieOptions { - Expires = new DateTimeOffset(DateTime.UtcNow.Add(Duration.LoginSessionLifetime)), + Expires = new DateTimeOffset(DateTime.UtcNow.Add(lifetime)), Secure = true, HttpOnly = true, SameSite = SameSiteMode.Strict, Domain = domain - }); + }; + } + + public static void SetSessionKeyCookie(this HttpContext context, string sessionKey, string domain) + { + context.Response.Cookies.Append(AuthConstants.UserSessionCookieName, sessionKey, GetCookieOptions(domain, Duration.LoginSessionLifetime)); } public static void RemoveSessionKeyCookie(this HttpContext context, string domain) { - context.Response.Cookies.Append(AuthConstants.UserSessionCookieName, string.Empty, new CookieOptions - { - Expires = DateTime.Now.AddDays(-1), - Secure = true, - HttpOnly = true, - SameSite = SameSiteMode.Strict, - Domain = domain - }); + context.Response.Cookies.Append(AuthConstants.UserSessionCookieName, string.Empty, GetCookieOptions(domain, TimeSpan.FromDays(-1))); } public static bool TryGetUserSession(this HttpContext context, [NotNullWhen(true)] out string? sessionToken)