fix: decode production admin session cookie
Remote Build and Deploy / deploy (push) Successful in 47s

This commit is contained in:
Simo committed 2026-07-11 22:42:19 +02:00
1 parent f08e56cf53
commit 02bbcba240
3 files changed
+16 -3

No files matched your search

+8 -1
View File
@@ -1,5 +1,5 @@
import { describe, expect, it } from "vitest";
import { shouldRedirectAdminRequest } from "./proxy-access";
import { shouldRedirectAdminRequest, usesSecureAuthCookie } from "./proxy-access";
describe("shouldRedirectAdminRequest", () => {
it("redirects anonymous admin requests before rendering", () => {
@@ -12,3 +12,10 @@ describe("shouldRedirectAdminRequest", () => {
expect(shouldRedirectAdminRequest("/news", null)).toBe(false);
});
});
describe("usesSecureAuthCookie", () => {
it("matches Auth.js production cookie naming", () => {
expect(usesSecureAuthCookie("production")).toBe(true);
expect(usesSecureAuthCookie("development")).toBe(false);
});
});
+4
View File
@@ -2,6 +2,10 @@ export interface ProxyToken {
rank?: unknown;
}
export function usesSecureAuthCookie(environment: string | undefined): boolean {
return environment === "production";
}
export function shouldRedirectAdminRequest(pathname: string, token: ProxyToken | null): boolean {
if (pathname !== "/admin" && !pathname.startsWith("/admin/")) return false;
return token === null;
+4 -2
View File
@@ -1,6 +1,6 @@
import { type NextRequest, NextResponse } from "next/server";
import { getToken } from "next-auth/jwt";
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
import { shouldRedirectAdminRequest, usesSecureAuthCookie } from "@/lib/proxy-access";
// Edge proxy (formerly "middleware"): Prisma can't run here, so we only forward
// the request path (so server components / the access guard can read it via
@@ -9,7 +9,9 @@ import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
export async function proxy(req: NextRequest) {
if (req.nextUrl.pathname === "/admin" || req.nextUrl.pathname.startsWith("/admin/")) {
const secret = process.env.AUTH_SECRET;
const token = secret ? await getToken({ req, secret }) : null;
const token = secret
? await getToken({ req, secret, secureCookie: usesSecureAuthCookie(process.env.NODE_ENV) })
: null;
if (shouldRedirectAdminRequest(req.nextUrl.pathname, token)) {
return NextResponse.redirect(new URL("/login", req.url));
}