Below is my node server where I am testing express session:
//all imports here
app.use(session({
secret: 'secret',
name: 'session',
saveUninitialized: true,
secure: false,
resave: false,
cookie:{
httpOnly: true,
maxAge: 10*60*1000
}
}))
app.get('/',(req,res)=>{
console.log(req.session);
res.sendFile(__dirname+"/index.html");
})
app.get('/login',(req,res)=>{
req.session.loggedIn=true;
req.session.user="Gratis";
res.send("successful");
}
app.get('/homepage',(req,res)=>{
if(!req.session.loggedIn) res.redirect('/');
else{console.log(req.session);
res.send(" Hello ");}
})
app.listen(3000);
The server us working fine, in the sense that on hitting the '/' route, exptress esnds a cookie "session" which is active for 10 mins. Means that the server would be able to track user for 10 mins right after the user hits '/' route. Now my question starts here:
Suppose user logs in after 7 minutes of hitting '/' route. Then req.session.username would be there in session for only 3 minutes cuzz 7 minutes would have already passed. So my question is, is there any way to prevent express from sending 'session' cookie only when user has hit '/login' route so that user is remebered for 10 mins.
I could thought of only sending custom cookie using res.cookie but it would destroy the purpose of express-session cuzz we don't have to handle cookies manually.
Thank You!!