All fixes

Add Secure, HttpOnly and SameSite flags

cookies-flags

A session cookie without Secure, HttpOnly and SameSite can be read by script, sent over plain HTTP, or replayed from another site. Set all three.

Next.js

  1. 1 Set cookie options when creating cookies in middleware or API routes
typescript
// When setting cookies
cookies().set('session', value, {
  secure: true,
  httpOnly: true,
  sameSite: 'lax',
  path: '/',
});

Does your app still have this?

Scan your domain