fix: bootstrap admin CSRF tokens
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 41s

This commit is contained in:
Simo committed 2026-08-02 11:46:43 +02:00
1 parent a57c73055f
commit b3245a18ea
8 files changed
+270 -45

No files matched your search

+3 -8
View File
@@ -17,11 +17,11 @@ import {
parseAdminNavConfig,
} from "@/lib/admin-nav-config";
import { db, User } from "@/lib/db";
import { setCsrfCookie } from "@/lib/foundation/security";
import { readCsrfCookieToken } from "@/lib/foundation/security";
import { canAccess, getAdminContext, PERMS } from "@/lib/permissions";
import { siteSettings } from "@/lib/services/site-settings";
// Request-time auth: requireStaff, CSRF cookie, and optional 2FA gate cannot be
// Request-time auth, existing CSRF cookie, and optional 2FA gate cannot be
// statically rendered. Child admin pages inherit this — leaf force-dynamic is redundant.
export const dynamic = "force-dynamic";
@@ -31,12 +31,7 @@ export default async function AdminLayout({
children: ReactNode;
}) {
const staff = await requireStaff();
let csrfToken = "";
try {
csrfToken = await setCsrfCookie();
} catch {
csrfToken = "";
}
const csrfToken = await readCsrfCookieToken();
if (await siteSettings.getBool("force_staff_2fa", false)) {
const u = await db
.select({ twoFactorConfirmedAt: User.twoFactorConfirmedAt })