fix: isolate proxy session decoding
Local Build and Deploy / deploy (push) Successful in 1m2s

This commit is contained in:
Simo committed 2026-07-12 13:39:25 +02:00
1 parent 47bd05f0d9
commit cdf180ee3f
3 files changed
+25 -2

No files matched your search

+13
View File
@@ -0,0 +1,13 @@
import { readFileSync } from "node:fs";
import { describe, expect, it } from "vitest";
describe("proxy authentication boundary", () => {
it("uses a database-free Auth.js decoder", () => {
const proxy = readFileSync("src/proxy.ts", "utf8");
const proxyAuth = readFileSync("src/lib/proxy-auth.ts", "utf8");
expect(proxy).toContain('from "@/lib/proxy-auth"');
expect(proxy).not.toContain('from "@/lib/auth"');
expect(proxyAuth).not.toMatch(/from\s+["'][^"']*(prisma|site-settings|credentials)[^"']*["']/i);
});
});
+10
View File
@@ -0,0 +1,10 @@
import NextAuth from "next-auth";
// Proxy authentication must only decode the Auth.js session. Importing the
// full CMS auth configuration here would also run Prisma/settings callbacks.
export const { auth: proxyAuth } = NextAuth({
trustHost: true,
secret: process.env.AUTH_SECRET,
session: { strategy: "jwt" },
providers: [],
});