fix: use canonical Auth.js session in proxy
Remote Build and Deploy / deploy (push) Successful in 43s

This commit is contained in:
Simo committed 2026-07-11 22:55:26 +02:00
1 parent cfa7998dd7
commit c4bf6488d0
3 files changed
+8 -39

No files matched your search

+7 -14
View File
@@ -1,21 +1,14 @@
import { type NextRequest, NextResponse } from "next/server";
import { getToken } from "next-auth/jwt";
import { authSessionCookieName, shouldRedirectAdminRequest } from "@/lib/proxy-access";
import { NextResponse } from "next/server";
import { auth } from "@/lib/auth";
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
// Edge proxy (formerly "middleware"): Prisma can't run here, so we only forward
// the request path (so server components / the access guard can read it via
// headers()) and normalize the real client IP. The DB-backed banned/maintenance
// checks happen in src/lib/access-guard.ts (Node runtime) from the root layout.
export async function proxy(req: NextRequest) {
if (req.nextUrl.pathname === "/admin" || req.nextUrl.pathname.startsWith("/admin/")) {
const secret = process.env.AUTH_SECRET;
const cookieName = authSessionCookieName(req.cookies.getAll().map((cookie) => cookie.name));
const token = secret && cookieName
? await getToken({ req, secret, cookieName })
: null;
if (shouldRedirectAdminRequest(req.nextUrl.pathname, token)) {
return NextResponse.redirect(new URL("/login", req.url));
}
export const proxy = auth((req) => {
if (shouldRedirectAdminRequest(req.nextUrl.pathname, req.auth?.user ?? null)) {
return NextResponse.redirect(new URL("/login", req.url));
}
const headers = new Headers(req.headers);
@@ -27,7 +20,7 @@ export async function proxy(req: NextRequest) {
"";
if (ip) headers.set("x-real-client-ip", ip);
return NextResponse.next({ request: { headers } });
}
});
export const config = {
matcher: ["/((?!api|_next/static|_next/image|assets|favicon.ico).*)"],