Files
DeskcommCRM/lib/auth/public-paths.ts
T
Rafael MelgaçoandClaude Opus 4.7 975b0242b5 feat(EPIC-11): admin layout + guard + banner [wave 1]
Foundation for the Super-Admin Platform sub-product:
- requirePlatformAdmin server helper: getUser → check platform_admins
  row + AAL2 (MFA recente). Redirects /admin/forbidden or /login/mfa.
- middleware.ts branches on host=admin.* OR path=/admin/* (early
  redirect to /login if no auth cookie). DB check stays server-side.
- AdminShell + PlatformModeBanner (sticky amber banner, role=region) +
  AdminSidebar (14 entries with distinct Phosphor icons).
- /admin redirects to /admin/dashboard (stub for S-11.02).
- /admin/forbidden 403 page outside the protected layout group.

In dev: works via http://localhost:3000/admin/* (no hosts file needed).
In prod: admin.deskcomm.com sub-domain via Vercel rewrites (deferred).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 13:09:49 -03:00

23 lines
500 B
TypeScript

/**
* Paths that bypass auth check in middleware.
* Match precedence: array order. First match wins.
*/
export const PUBLIC_PATHS: RegExp[] = [
/^\/$/,
/^\/login(\/.*)?$/,
/^\/403$/,
/^\/admin\/forbidden$/,
/^\/404$/,
/^\/500$/,
/^\/503$/,
/^\/api\/v1\/health$/,
/^\/api\/v1\/webhooks\//,
/^\/_next\//,
/^\/favicon\.ico$/,
/^\/team\/accept-invite\/.+$/,
];
export function isPublicPath(pathname: string): boolean {
return PUBLIC_PATHS.some((re) => re.test(pathname));
}