🐛 Fix: [#30] 쿠키 secure=not settings.debug로 수정
This commit is contained in:
@@ -1,3 +1,5 @@
|
|||||||
|
from django.conf import settings
|
||||||
|
|
||||||
from django.shortcuts import get_object_or_404
|
from django.shortcuts import get_object_or_404
|
||||||
|
|
||||||
from rest_framework.views import APIView
|
from rest_framework.views import APIView
|
||||||
@@ -28,7 +30,7 @@ class RefreshAPIView(APIView):
|
|||||||
serializer = TokenRefreshSerializer(data={'refresh': refresh})
|
serializer = TokenRefreshSerializer(data={'refresh': refresh})
|
||||||
if serializer.is_valid():
|
if serializer.is_valid():
|
||||||
res = Response({"access": serializer.validated_data['access']}, status=status.HTTP_200_OK)
|
res = Response({"access": serializer.validated_data['access']}, status=status.HTTP_200_OK)
|
||||||
res.set_cookie("refresh", serializer.validated_data['refresh'], httponly=True, samesite="Lax", secure=True)
|
res.set_cookie("refresh", serializer.validated_data['refresh'], httponly=True, samesite="Lax", secure=not settings.DEBUG)
|
||||||
return res
|
return res
|
||||||
except TokenError as e:
|
except TokenError as e:
|
||||||
return Response({"message": f"Invalid token: {e}"}, status=status.HTTP_401_UNAUTHORIZED)
|
return Response({"message": f"Invalid token: {e}"}, status=status.HTTP_401_UNAUTHORIZED)
|
||||||
@@ -75,7 +77,7 @@ class LoginAPIView(APIView):
|
|||||||
},
|
},
|
||||||
status=status.HTTP_200_OK,
|
status=status.HTTP_200_OK,
|
||||||
)
|
)
|
||||||
res.set_cookie("refresh", serializer.validated_data['refresh'], httponly=True, samesite="Lax", secure=True)
|
res.set_cookie("refresh", serializer.validated_data['refresh'], httponly=True, samesite="Lax", secure=not settings.DEBUG)
|
||||||
return res
|
return res
|
||||||
else:
|
else:
|
||||||
return Response(serializer.errors)
|
return Response(serializer.errors)
|
||||||
|
|||||||
Reference in New Issue
Block a user