✏️ Fix: [#53] https에서만 세션 쿠키 전송 설정 및 엑세스 토큰 유효기간 롤백

This commit is contained in:
sm4640
2025-05-13 15:19:43 +09:00
parent e3f5539fd2
commit a8d65ece5c

View File

@@ -174,7 +174,7 @@ REST_FRAMEWORK = {
REST_USE_JWT = True REST_USE_JWT = True
SIMPLE_JWT = { SIMPLE_JWT = {
'ACCESS_TOKEN_LIFETIME': timedelta(days=7), # minutes = 15 'ACCESS_TOKEN_LIFETIME': timedelta(minutes= 15),
'REFRESH_TOKEN_LIFETIME': timedelta(days=7), 'REFRESH_TOKEN_LIFETIME': timedelta(days=7),
'ROTATE_REFRESH_TOKENS': True, 'ROTATE_REFRESH_TOKENS': True,
'BLACKLIST_AFTER_ROTATION': True, 'BLACKLIST_AFTER_ROTATION': True,
@@ -213,7 +213,7 @@ SESSION_EXPIRE_AT_BROWSER_CLOSE = True
SESSION_COOKIE_AGE = 86400 SESSION_COOKIE_AGE = 86400
# https에서만 세션 쿠키가 전송 (default false) https 배포 시 true로 # https에서만 세션 쿠키가 전송 (default false) https 배포 시 true로
SESSION_COOKIE_SECURE = False SESSION_COOKIE_SECURE = True
GOOGLE_CLIENT_ID = env('GOOGLE_CLIENT_ID') GOOGLE_CLIENT_ID = env('GOOGLE_CLIENT_ID')