-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathproxy.ts
More file actions
85 lines (75 loc) · 2.99 KB
/
Copy pathproxy.ts
File metadata and controls
85 lines (75 loc) · 2.99 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
import { NextRequest, NextResponse } from "next/server";
import { auth0 } from "@/lib/auth0";
import { AUTH_SIGNIN_HREF } from "@/lib/console/auth-login";
import { devMockResponse } from "@/lib/console/dev-mock";
function copyAuthCookies(from: NextResponse, to: NextResponse): NextResponse {
from.cookies.getAll().forEach((cookie) => {
to.cookies.set(cookie);
});
return to;
}
// Routes that exist only for a signed-in user. Signed-out requests are
// redirected here, in the proxy, rather than by the page: a client-side
// redirect runs after the console chrome has already painted, so a cold
// signed-out load flashed the sidebar for a frame before landing on /login.
// Home keeps the in-shell sign-in wall; Install redirects before the shell.
function isSessionOnlyPath(pathname: string): boolean {
return pathname === "/" || pathname === "/install";
}
export async function proxy(request: NextRequest) {
// Dev-only: answer auth + PymtHouse endpoints from fixtures so auth-gated
// surfaces can be designed without credentials. See lib/console/dev-mock.ts.
const devMock =
process.env.NODE_ENV !== "production" &&
process.env.CONSOLE_DEV_MOCK === "1";
if (devMock) {
const mocked = devMockResponse(
request.nextUrl.pathname,
request.nextUrl.searchParams,
new URL(
`${request.nextUrl.pathname}${request.nextUrl.search}`,
`${request.nextUrl.protocol}//${request.headers.get("host") ?? request.nextUrl.host}`
).href
);
if (mocked) return mocked;
}
const authRes = await auth0.middleware(request);
const { pathname } = request.nextUrl;
// The proxy manages provider cookies and early signed-out routing.
// Admission is checked in Node page/API services on every protected request.
if (!isSessionOnlyPath(pathname)) {
return authRes;
}
const redirectTo = (path: string) =>
copyAuthCookies(authRes, NextResponse.redirect(new URL(path, request.url)));
const legacyReferralCode = request.nextUrl.searchParams.get("ref")?.trim();
if (pathname === "/" && legacyReferralCode) {
const waitlistUrl = new URL("/waitlist", request.url);
waitlistUrl.searchParams.set("ref", legacyReferralCode);
return copyAuthCookies(authRes, NextResponse.redirect(waitlistUrl));
}
try {
const session = await auth0.getSession(request);
// The dev mock has no real session cookie but is always "signed in" —
// its /auth/profile fixture is what the client reads.
const signedIn = devMock || !!session?.user;
if (!signedIn) {
return isSessionOnlyPath(pathname)
? redirectTo(AUTH_SIGNIN_HREF)
: authRes;
}
// `/` is a pure redirect in both auth states. Admission and admin landing
// run on `/login` after Auth0 and on `/home` via requireConsolePage.
if (pathname === "/") {
return redirectTo("/home");
}
} catch {
return authRes;
}
return authRes;
}
export const config = {
matcher: [
"/((?!_next/static|_next/image|favicon.ico|sitemap.xml|robots.txt).*)",
],
};