32 lines
1.3 KiB
TypeScript
32 lines
1.3 KiB
TypeScript
import { type NextRequest, NextResponse } from "next/server";
|
|
import { getToken } from "next-auth/jwt";
|
|
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
|
|
|
|
// Edge proxy (formerly "middleware"): Prisma can't run here, so we only forward
|
|
// the request path (so server components / the access guard can read it via
|
|
// headers()) and normalize the real client IP. The DB-backed banned/maintenance
|
|
// checks happen in src/lib/access-guard.ts (Node runtime) from the root layout.
|
|
export async function proxy(req: NextRequest) {
|
|
if (req.nextUrl.pathname === "/admin" || req.nextUrl.pathname.startsWith("/admin/")) {
|
|
const secret = process.env.AUTH_SECRET;
|
|
const token = secret ? await getToken({ req, secret }) : null;
|
|
if (shouldRedirectAdminRequest(req.nextUrl.pathname, token)) {
|
|
return NextResponse.redirect(new URL("/login", req.url));
|
|
}
|
|
}
|
|
|
|
const headers = new Headers(req.headers);
|
|
headers.set("x-pathname", req.nextUrl.pathname);
|
|
const ip =
|
|
req.headers.get("cf-connecting-ip") ??
|
|
req.headers.get("x-forwarded-for")?.split(",")[0]?.trim() ??
|
|
req.headers.get("x-real-ip") ??
|
|
"";
|
|
if (ip) headers.set("x-real-client-ip", ip);
|
|
return NextResponse.next({ request: { headers } });
|
|
}
|
|
|
|
export const config = {
|
|
matcher: ["/((?!api|_next/static|_next/image|assets|favicon.ico).*)"],
|
|
};
|