Aron Høyer
Aron Høyer

Reputation: 157

Express.js httpOnly cookie not being set

I've set up an API with a create user and an auth route. The auth route should set an httpOnly cookie containing a JWT, and should send JSON for the client to store in localhost.

In the front-end I'm doing a simple fetch.

The server responds 200 and with the JSON I expect, but somehow, the cookie doesn't get set.

However, in Postman, the cookie does indeed get set.

Express server

const express = require('express')
const cors = require('cors')

// boilerplate stuff

app.use(express.json())
app.use(cors({ origin: 'http://localhost:3000', credentials: true }))

app.post('auth', (req, res) => {
  // fetch user from db, validation, bla bla bla

  const token = jwt.sign({ issuer: user.id }, keys.private, { algorithm: 'RS256' })

  res.cookie('token', token, { httpOnly: true })
  res.json(user)
})

Next.js front-end

const handleSubmit = async (e) => {
  e.preventDefault()
  try {
    const res = await fetch('http://localhost:5000/api/v1/auth', {
      method: 'post',
      mode: 'cors',
      credentials: 'include',
      headers: {
        'content-type': 'application/json',
        'accept': 'application/json',
      },
      body: JSON.stringify(formState),
    })
    const data = await res.json()
    console.log(data)
  } catch (err) {
    console.error(err)
    setError(err.message)
  }
}

Upvotes: 3

Views: 2787

Answers (1)

Aron Høyer
Aron Høyer

Reputation: 157

'Twas resolved.

I was looking in Session Storage as opposed to Cookies in my devtools.

Upvotes: 3

Related Questions