mirror of
https://github.com/Open-Dev-Society/OpenStock.git
synced 2026-10-02 04:54:32 +08:00
- Watchlist and alert actions took a userId from the client, so any signed-in user could add, remove or delete another user's data. They now read the session. - middleware/index.ts was never loaded by Next.js (empty middleware manifest); moved to middleware.ts so signed-out requests redirect before any page code runs. - Mongo connection log no longer prints the password. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
25 lines
807 B
TypeScript
25 lines
807 B
TypeScript
import { NextRequest, NextResponse } from 'next/server';
|
|
import { getSessionCookie } from "better-auth/cookies";
|
|
|
|
const PUBLIC_PATHS = new Set(['/', '/about', '/help', '/terms', '/api-docs', '/sponsor']);
|
|
|
|
export async function middleware(request: NextRequest) {
|
|
// The marketing site is public
|
|
if (PUBLIC_PATHS.has(request.nextUrl.pathname)) return NextResponse.next();
|
|
|
|
const sessionCookie = getSessionCookie(request);
|
|
|
|
// Check cookie presence - prevents obviously unauthorized users
|
|
if (!sessionCookie) {
|
|
return NextResponse.redirect(new URL('/sign-in', request.url));
|
|
}
|
|
|
|
return NextResponse.next();
|
|
}
|
|
|
|
export const config = {
|
|
matcher: [
|
|
'/((?!api|_next/static|_next/image|favicon.ico|sign-in|sign-up|forgot-password|reset-password|assets).*)',
|
|
],
|
|
};
|