fix: use canonical Auth.js session in proxy
Remote Build and Deploy / deploy (push) Successful in 43s
Remote Build and Deploy / deploy (push) Successful in 43s
This commit is contained in:
1 parent
cfa7998dd7
commit
c4bf6488d0
3 files changed
+8
-39
No files matched your search
@@ -1,5 +1,5 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { authSessionCookieName, shouldRedirectAdminRequest } from "./proxy-access";
|
||||
import { shouldRedirectAdminRequest } from "./proxy-access";
|
||||
|
||||
describe("shouldRedirectAdminRequest", () => {
|
||||
it("redirects anonymous admin requests before rendering", () => {
|
||||
@@ -12,18 +12,3 @@ describe("shouldRedirectAdminRequest", () => {
|
||||
expect(shouldRedirectAdminRequest("/news", null)).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
describe("authSessionCookieName", () => {
|
||||
it("detects secure and unprefixed Auth.js cookies from the request", () => {
|
||||
expect(authSessionCookieName(["__Secure-authjs.session-token"])).toBe("__Secure-authjs.session-token");
|
||||
expect(authSessionCookieName(["authjs.session-token"])).toBe("authjs.session-token");
|
||||
});
|
||||
|
||||
it("detects a chunked production session cookie", () => {
|
||||
expect(authSessionCookieName(["__Secure-authjs.session-token.0", "__Secure-authjs.session-token.1"])).toBe("__Secure-authjs.session-token");
|
||||
});
|
||||
|
||||
it("returns null when no session cookie exists", () => {
|
||||
expect(authSessionCookieName(["theme"])).toBeNull();
|
||||
});
|
||||
});
|
||||
@@ -2,15 +2,6 @@ export interface ProxyToken {
|
||||
rank?: unknown;
|
||||
}
|
||||
|
||||
const AUTH_COOKIE_NAMES = ["__Secure-authjs.session-token", "authjs.session-token"] as const;
|
||||
|
||||
export function authSessionCookieName(cookieNames: readonly string[]): string | null {
|
||||
for (const base of AUTH_COOKIE_NAMES) {
|
||||
if (cookieNames.some((name) => name === base || name.startsWith(`${base}.`))) return base;
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
export function shouldRedirectAdminRequest(pathname: string, token: ProxyToken | null): boolean {
|
||||
if (pathname !== "/admin" && !pathname.startsWith("/admin/")) return false;
|
||||
return token === null;
|
||||
|
||||
+7
-14
@@ -1,21 +1,14 @@
|
||||
import { type NextRequest, NextResponse } from "next/server";
|
||||
import { getToken } from "next-auth/jwt";
|
||||
import { authSessionCookieName, shouldRedirectAdminRequest } from "@/lib/proxy-access";
|
||||
import { NextResponse } from "next/server";
|
||||
import { auth } from "@/lib/auth";
|
||||
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
|
||||
|
||||
// Edge proxy (formerly "middleware"): Prisma can't run here, so we only forward
|
||||
// the request path (so server components / the access guard can read it via
|
||||
// headers()) and normalize the real client IP. The DB-backed banned/maintenance
|
||||
// checks happen in src/lib/access-guard.ts (Node runtime) from the root layout.
|
||||
export async function proxy(req: NextRequest) {
|
||||
if (req.nextUrl.pathname === "/admin" || req.nextUrl.pathname.startsWith("/admin/")) {
|
||||
const secret = process.env.AUTH_SECRET;
|
||||
const cookieName = authSessionCookieName(req.cookies.getAll().map((cookie) => cookie.name));
|
||||
const token = secret && cookieName
|
||||
? await getToken({ req, secret, cookieName })
|
||||
: null;
|
||||
if (shouldRedirectAdminRequest(req.nextUrl.pathname, token)) {
|
||||
return NextResponse.redirect(new URL("/login", req.url));
|
||||
}
|
||||
export const proxy = auth((req) => {
|
||||
if (shouldRedirectAdminRequest(req.nextUrl.pathname, req.auth?.user ?? null)) {
|
||||
return NextResponse.redirect(new URL("/login", req.url));
|
||||
}
|
||||
|
||||
const headers = new Headers(req.headers);
|
||||
@@ -27,7 +20,7 @@ export async function proxy(req: NextRequest) {
|
||||
"";
|
||||
if (ip) headers.set("x-real-client-ip", ip);
|
||||
return NextResponse.next({ request: { headers } });
|
||||
}
|
||||
});
|
||||
|
||||
export const config = {
|
||||
matcher: ["/((?!api|_next/static|_next/image|assets|favicon.ico).*)"],
|
||||
|
||||
Reference in new issue
Block a user