From 904260fd44729ed2f75267daebd70499305121f8 Mon Sep 17 00:00:00 2001 From: Nicolas Giard Date: Thu, 23 May 2024 23:01:38 -0400 Subject: [PATCH] fix: set no-store cache control on jwt renew response --- server/core/auth.js | 3 +++ 1 file changed, 3 insertions(+) diff --git a/server/core/auth.js b/server/core/auth.js index 38f0b3b8..91ef2101 100644 --- a/server/core/auth.js +++ b/server/core/auth.js @@ -156,6 +156,9 @@ module.exports = { } else { res.cookie('jwt', newToken.token, { expires: DateTime.utc().plus({ days: 365 }).toJSDate() }) } + + // Avoid caching this response + res.set('Cache-Control', 'no-store') } catch (errc) { WIKI.logger.warn(errc) return next()