Files
ravixalgorithmandClaude Opus 5.5 f1045c2ab4 fix(security): scope server actions to the signed-in user, load middleware, redact DB credentials
- Watchlist and alert actions took a userId from the client, so any signed-in user
  could add, remove or delete another user's data. They now read the session.
- middleware/index.ts was never loaded by Next.js (empty middleware manifest); moved
  to middleware.ts so signed-out requests redirect before any page code runs.
- Mongo connection log no longer prints the password.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 15:28:00 +05:30

25 lines
807 B
TypeScript

import { NextRequest, NextResponse } from 'next/server';
import { getSessionCookie } from "better-auth/cookies";
const PUBLIC_PATHS = new Set(['/', '/about', '/help', '/terms', '/api-docs', '/sponsor']);
export async function middleware(request: NextRequest) {
// The marketing site is public
if (PUBLIC_PATHS.has(request.nextUrl.pathname)) return NextResponse.next();
const sessionCookie = getSessionCookie(request);
// Check cookie presence - prevents obviously unauthorized users
if (!sessionCookie) {
return NextResponse.redirect(new URL('/sign-in', request.url));
}
return NextResponse.next();
}
export const config = {
matcher: [
'/((?!api|_next/static|_next/image|favicon.ico|sign-in|sign-up|forgot-password|reset-password|assets).*)',
],
};