fix: detect deployed Auth.js session cookie
Remote Build and Deploy / deploy (push) Successful in 44s
Remote Build and Deploy / deploy (push) Successful in 44s
This commit is contained in:
1 parent
02bbcba240
commit
cfa7998dd7
3 files changed
+24
-10
No files matched your search
+4
-3
@@ -1,6 +1,6 @@
|
||||
import { type NextRequest, NextResponse } from "next/server";
|
||||
import { getToken } from "next-auth/jwt";
|
||||
import { shouldRedirectAdminRequest, usesSecureAuthCookie } from "@/lib/proxy-access";
|
||||
import { authSessionCookieName, shouldRedirectAdminRequest } from "@/lib/proxy-access";
|
||||
|
||||
// Edge proxy (formerly "middleware"): Prisma can't run here, so we only forward
|
||||
// the request path (so server components / the access guard can read it via
|
||||
@@ -9,8 +9,9 @@ import { shouldRedirectAdminRequest, usesSecureAuthCookie } from "@/lib/proxy-ac
|
||||
export async function proxy(req: NextRequest) {
|
||||
if (req.nextUrl.pathname === "/admin" || req.nextUrl.pathname.startsWith("/admin/")) {
|
||||
const secret = process.env.AUTH_SECRET;
|
||||
const token = secret
|
||||
? await getToken({ req, secret, secureCookie: usesSecureAuthCookie(process.env.NODE_ENV) })
|
||||
const cookieName = authSessionCookieName(req.cookies.getAll().map((cookie) => cookie.name));
|
||||
const token = secret && cookieName
|
||||
? await getToken({ req, secret, cookieName })
|
||||
: null;
|
||||
if (shouldRedirectAdminRequest(req.nextUrl.pathname, token)) {
|
||||
return NextResponse.redirect(new URL("/login", req.url));
|
||||
|
||||
Reference in new issue
Block a user