// Customer session, stored in an httpOnly cookie. Server-only: the access token // must never reach the browser's JavaScript. import type { Context } from 'hono'; import { getCookie, setCookie, deleteCookie } from 'hono/cookie'; import { CUSTOMER_TOKEN_COOKIE } from '@/services/shopify/customer'; export function getSessionToken(c: Context): string | null { return getCookie(c, CUSTOMER_TOKEN_COOKIE) ?? null; } export function setSessionToken( c: Context, accessToken: string, expiresAt: string ): void { const expires = new Date(expiresAt); setCookie(c, CUSTOMER_TOKEN_COOKIE, accessToken, { httpOnly: true, secure: import.meta.env.PROD, sameSite: 'Lax', path: '/', expires: Number.isNaN(expires.getTime()) ? undefined : expires, }); } export function clearSessionToken(c: Context): void { deleteCookie(c, CUSTOMER_TOKEN_COOKIE, { path: '/' }); }