perf(html): replace proxyAuth with getToken to remove set-cookie; add Cache-Control per auth state
This commit is contained in:
1 parent
2799b63943
commit
7c1f8d709e
3 files changed
+28
-12
No files matched your search
@@ -1,4 +1,5 @@
|
||||
export interface ProxyToken {
|
||||
sub?: string;
|
||||
rank?: unknown;
|
||||
}
|
||||
|
||||
|
||||
@@ -2,14 +2,12 @@ import { readFileSync } from "node:fs";
|
||||
import { describe, expect, it } from "vitest";
|
||||
|
||||
describe("proxy authentication boundary", () => {
|
||||
it("uses a database-free Auth.js decoder", () => {
|
||||
it("uses getToken directly without database-dependent Auth.js config", () => {
|
||||
const proxy = readFileSync("src/proxy.ts", "utf8");
|
||||
const proxyAuth = readFileSync("src/lib/proxy-auth.ts", "utf8");
|
||||
|
||||
expect(proxy).toContain('from "@/lib/proxy-auth"');
|
||||
expect(proxy).not.toContain('from "@/lib/proxy-auth"');
|
||||
expect(proxy).not.toContain('from "@/lib/auth"');
|
||||
expect(proxyAuth).not.toMatch(
|
||||
/from\s+["'][^"']*(db|site-settings|credentials|prisma)[^"']*["']/i,
|
||||
);
|
||||
expect(proxy).toContain("getToken");
|
||||
expect(proxy).toContain("next-auth/jwt");
|
||||
});
|
||||
});
|
||||
+23
-6
@@ -1,7 +1,8 @@
|
||||
import { NextResponse } from "next/server";
|
||||
import { getToken } from "next-auth/jwt";
|
||||
import { env } from "@/env";
|
||||
import { buildContentSecurityPolicy, createCspNonce } from "@/lib/csp";
|
||||
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
|
||||
import { proxyAuth } from "@/lib/proxy-auth";
|
||||
|
||||
const SECURITY_HEADERS: Record<string, string> = {
|
||||
"X-Content-Type-Options": "nosniff",
|
||||
@@ -12,10 +13,14 @@ const SECURITY_HEADERS: Record<string, string> = {
|
||||
"Strict-Transport-Security": "max-age=63072000; includeSubDomains; preload",
|
||||
};
|
||||
|
||||
export const proxy = proxyAuth((req) => {
|
||||
if (
|
||||
shouldRedirectAdminRequest(req.nextUrl.pathname, req.auth?.user ?? null)
|
||||
) {
|
||||
export const proxy = async (req: import("next/server").NextRequest) => {
|
||||
const token = await getToken({
|
||||
req,
|
||||
secret: env.AUTH_SECRET,
|
||||
secureCookie: true,
|
||||
});
|
||||
|
||||
if (shouldRedirectAdminRequest(req.nextUrl.pathname, token)) {
|
||||
return NextResponse.redirect(new URL("/login", req.url));
|
||||
}
|
||||
|
||||
@@ -33,6 +38,18 @@ export const proxy = proxyAuth((req) => {
|
||||
"";
|
||||
if (ip) headers.set("x-real-client-ip", ip);
|
||||
|
||||
if (token) {
|
||||
headers.set(
|
||||
"Cache-Control",
|
||||
"private, no-cache, no-store, max-age=0, must-revalidate",
|
||||
);
|
||||
} else {
|
||||
headers.set(
|
||||
"Cache-Control",
|
||||
"public, max-age=60, s-maxage=300, stale-while-revalidate=300",
|
||||
);
|
||||
}
|
||||
|
||||
const response = NextResponse.next({ request: { headers } });
|
||||
|
||||
for (const [key, value] of Object.entries(SECURITY_HEADERS)) {
|
||||
@@ -41,7 +58,7 @@ export const proxy = proxyAuth((req) => {
|
||||
response.headers.set("Content-Security-Policy", csp);
|
||||
|
||||
return response;
|
||||
});
|
||||
};
|
||||
|
||||
export const config = {
|
||||
matcher: ["/((?!api|_next/static|_next/image|assets|favicon.ico).*)"],
|
||||
|
||||
Reference in new issue
Block a user