Confusing cookieParser & cookieSession #722

Closed
scriby opened this Issue Jan 7, 2013 · 2 comments

Comments

Projects
None yet
3 participants

scriby commented Jan 7, 2013

My first attempt at getting the session cookie store to work was like this:

app.use(express.cookieParser(secret));
app.use(express.cookieSession({
    secret: secret
}));

But for some reason it doesn't work if you pass the secret to the cookieParser as well. Whether this is intended or not, I don't know, but I found it confusing.

After stepping through the code I figured out this combination would work:

app.use(express.cookieParser());
app.use(express.cookieSession({
    secret: secret
}));
Member

tj commented Jan 13, 2013

it should try cookieParser's secret first for legacy, and then the one passed via options

jonathanong was assigned Dec 4, 2013

Contributor

jonathanong commented Feb 23, 2014

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment