set admin behind a cookie and check role on profile
This commit is contained in:
+31
-9
@@ -12,15 +12,37 @@ const ALWAYS_ALLOW = new Set<string>([
|
||||
"/sitemap.xml",
|
||||
]);
|
||||
|
||||
// Match common public/static file extensions so middleware never blocks them
|
||||
const PUBLIC_FILE = /\.(?:svg|png|jpg|jpeg|gif|webp|ico|css|js|map|txt|xml|json|woff|woff2|ttf|eot)$/i;
|
||||
const PUBLIC_FILE =
|
||||
/\.(?:svg|png|jpg|jpeg|gif|webp|ico|css|js|map|txt|xml|json|woff|woff2|ttf|eot)$/i;
|
||||
|
||||
export function middleware(req: NextRequest) {
|
||||
if (!LAUNCH_ONLY_ROOT) return NextResponse.next();
|
||||
|
||||
const { pathname } = req.nextUrl;
|
||||
|
||||
// ✅ Always allow Next internals + static assets (public/ and _next/)
|
||||
// =========================
|
||||
// 1) Admin gate (always on)
|
||||
// =========================
|
||||
if (pathname.startsWith("/admin")) {
|
||||
const token = req.cookies.get("bb_access_token")?.value;
|
||||
const role = req.cookies.get("bb_role")?.value; // optional
|
||||
|
||||
const ok = !!token && (!role || role === "ADMIN");
|
||||
|
||||
if (!ok) {
|
||||
const url = req.nextUrl.clone();
|
||||
url.pathname = "/login";
|
||||
url.searchParams.set("next", pathname);
|
||||
return NextResponse.redirect(url);
|
||||
}
|
||||
|
||||
return NextResponse.next();
|
||||
}
|
||||
|
||||
// =====================================
|
||||
// 2) Launch-only gate (your existing one)
|
||||
// =====================================
|
||||
if (!LAUNCH_ONLY_ROOT) return NextResponse.next();
|
||||
|
||||
// ✅ Always allow Next internals + static assets
|
||||
if (
|
||||
pathname.startsWith("/_next") ||
|
||||
pathname.startsWith("/favicon") ||
|
||||
@@ -31,17 +53,17 @@ export function middleware(req: NextRequest) {
|
||||
return NextResponse.next();
|
||||
}
|
||||
|
||||
// ✅ Allow the root + a few public files
|
||||
if (ALWAYS_ALLOW.has(pathname)) return NextResponse.next();
|
||||
|
||||
// 🚫 Everything else: hide it
|
||||
return NextResponse.rewrite(new URL("/404", req.url));
|
||||
}
|
||||
|
||||
|
||||
` 1`
|
||||
export const config = {
|
||||
// Run middleware on everything *except* Next internals and obvious static files.
|
||||
// This keeps launch gating from ever breaking your logo/images/fonts/etc.
|
||||
matcher: [
|
||||
// run on everything except Next internals + obvious static files
|
||||
"/((?!_next/static|_next/image|favicon.ico|robots.txt|sitemap.xml|.*\\.(?:svg|png|jpg|jpeg|gif|webp|ico|css|js|map|txt|xml|json|woff|woff2|ttf|eot)).*)",
|
||||
],
|
||||
|
||||
};
|
||||
Reference in New Issue
Block a user