From 3f9b14e3c1d7f47d9b3e48b94b3b5bf2c722205e Mon Sep 17 00:00:00 2001 From: Wes Bos Date: Tue, 15 May 2018 22:15:36 -0400 Subject: migrate to cookies for jwt --- backend/src/resolvers/Mutation.js | 24 +++++++++++++++++++----- 1 file changed, 19 insertions(+), 5 deletions(-) (limited to 'backend/src/resolvers/Mutation.js') diff --git a/backend/src/resolvers/Mutation.js b/backend/src/resolvers/Mutation.js index 268b348..153833d 100644 --- a/backend/src/resolvers/Mutation.js +++ b/backend/src/resolvers/Mutation.js @@ -22,10 +22,18 @@ const mutations = { info ); - return { - token: jwt.sign({ userId: user.id }, process.env.APP_SECRET), - user, - }; + const token = jwt.sign({ userId: user.id }, process.env.APP_SECRET); + ctx.response.cookie('token', token, { + maxAge: 1000 * 60 * 60 * 24 * 365, + httpOnly: true, + }); + return { user }; + }, + + async signout(parent, args, ctx, info) { + ctx.response.clearCookie('token'); + // TODO: What do we return here? + return { id: 'abc123' }; }, async signin(parent, { email, password }, ctx, info) { @@ -38,8 +46,14 @@ const mutations = { if (!valid) { throw new Error('Invalid password'); } + // set the cookie + const token = jwt.sign({ userId: user.id }, process.env.APP_SECRET); + ctx.response.cookie('token', token, { + maxAge: 1000 * 60 * 60 * 24 * 365, + httpOnly: true, + }); return { - token: jwt.sign({ userId: user.id }, process.env.APP_SECRET), + token, user, }; }, -- cgit v1.3