From 965a7e8798ee27c4737469c4fa68269ec0c99eda Mon Sep 17 00:00:00 2001 From: Michael Gerni Date: Mon, 28 Sep 2026 23:06:27 -0400 Subject: [PATCH] fix persistent sessions --- app_setup.py | 6 ++++-- taskapp.py | 4 ++++ 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/app_setup.py b/app_setup.py index 85b1d56..df5a099 100644 --- a/app_setup.py +++ b/app_setup.py @@ -1,7 +1,7 @@ from flask import Flask import config from recaptcha_helper import Recaptcha - +from datetime import timedelta app = Flask(__name__) @@ -10,7 +10,9 @@ # Set secret key for Flask App. app.config['SECRET_KEY'] = config.SECRET_KEY - +app.config['PERMANENT_SESSION_LIFETIME'] = timedelta(days=30) +app.config['SESSION_COOKIE_SECURE'] = isProd +app.config['SESSION_COOKIE_SAMESITE'] = 'Lax' if isProd: # Keys for Google reCAPTCHA. app.config['RECAPTCHA_SITE_KEY'] = config.RECAPTCHA_SITE_KEY diff --git a/taskapp.py b/taskapp.py index 93d1114..dcedfa4 100644 --- a/taskapp.py +++ b/taskapp.py @@ -127,6 +127,8 @@ def get_related_completed_item_ids_for_task(user, tier: str, task_id: str) -> li # Base route for the website, renders hero.html @app.route('/') def index(): + if session.get('logged_in'): + return redirect(url_for('dashboard')) return render_template('hero.html') # Register route, renders registerV2.html on GET request. @@ -211,6 +213,8 @@ def register_user(): # On POST request, verifies the users input and logs the user in. @app.route('/login/', methods= ['GET', 'POST']) def login(): + if request.method == 'GET' and session.get('logged_in'): + return redirect(url_for('dashboard')) try: error = None coll = db['users']