Skip to content

Commit 7ee5a03

Browse files
committed
Enhance middleware for route handling and authorization
- Added new public paths to the middleware to allow unauthenticated access to specific routes, improving user experience on the dashboard. - Updated the host guard logic to ensure proper handling of tracking-only routes, returning a 404 for unauthorized access. - Refactored the matcher configuration to streamline route matching for the middleware, enhancing overall performance and security.
1 parent 16dc90c commit 7ee5a03

1 file changed

Lines changed: 43 additions & 17 deletions

File tree

‎middleware.ts‎

Lines changed: 43 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -25,38 +25,64 @@ const TRACKING_ALLOWED = [
2525
/^\/api\/webhooks\//,
2626
/^\/_next\/static\//,
2727
/^\/_next\/image/,
28-
/^\/favicon\.ico$/,
28+
/^\/favicon/,
29+
/^\/assets\//,
30+
]
31+
32+
// Routes that bypass the auth guard on the dashboard host.
33+
const PUBLIC_PATHS = [
34+
/^\/login(\/|$)/,
35+
/^\/api\/auth\//,
36+
/^\/api\/v1\//,
37+
/^\/api\/webhooks\//,
38+
/^\/api\/public\//,
39+
/^\/img\//,
40+
/^\/accept-invite(\/|$)/,
41+
/^\/unsubscribe(\/|$)/,
42+
/^\/confirm(\/|$)/,
43+
/^\/f\//,
44+
/^\/form\//,
45+
/^\/t\//,
46+
/^\/r\//,
2947
]
3048

3149
const authMiddleware = withAuth({
3250
pages: { signIn: '/login' },
3351
})
3452

3553
export default function middleware(req: NextRequest) {
36-
const host = req.headers.get('host') || ''
54+
const host = (req.headers.get('host') || '').toLowerCase()
3755
const path = req.nextUrl.pathname
3856

39-
// If TRACKING_URL is configured to a different host than APP_URL, restrict
40-
// that host to tracking-only routes. Anything else 404s, so phishing scanners
41-
// and curious crawlers won't see the login page on the tracker domain.
42-
if (TRACKING_HOST && APP_HOST && TRACKING_HOST !== APP_HOST && host === TRACKING_HOST) {
43-
const allowed = TRACKING_ALLOWED.some((re) => re.test(path))
44-
if (!allowed) {
45-
return new NextResponse('Not Found', { status: 404 })
57+
// Host guard: if a separate tracking host is configured, lock it to
58+
// tracking-only routes. Phishing scanners, crawlers, and casual visitors
59+
// see a 404 on everything else, including /login.
60+
if (
61+
TRACKING_HOST &&
62+
APP_HOST &&
63+
TRACKING_HOST !== APP_HOST &&
64+
host === TRACKING_HOST
65+
) {
66+
if (TRACKING_ALLOWED.some((re) => re.test(path))) {
67+
return NextResponse.next()
4668
}
47-
return NextResponse.next()
69+
return new NextResponse('Not Found', {
70+
status: 404,
71+
headers: {
72+
'Content-Type': 'text/plain',
73+
'Cache-Control': 'no-store, no-cache, must-revalidate',
74+
},
75+
})
4876
}
4977

50-
// Fall through to NextAuth middleware on the dashboard host.
78+
// Dashboard host: skip auth for public routes, otherwise enforce it.
79+
if (PUBLIC_PATHS.some((re) => re.test(path))) {
80+
return NextResponse.next()
81+
}
5182
// eslint-disable-next-line @typescript-eslint/no-explicit-any
5283
return (authMiddleware as any)(req)
5384
}
5485

5586
export const config = {
56-
matcher: [
57-
'/((?!api/auth|api/v1|api/webhooks|api/public|img|login|accept-invite|unsubscribe|confirm|f|form|t|r|_next/static|_next/image|favicon.ico).*)',
58-
'/r/:path*',
59-
'/t/:path*',
60-
'/unsubscribe/:path*',
61-
],
87+
matcher: ['/((?!_next/static|_next/image|favicon.ico).*)'],
6288
}

0 commit comments

Comments
 (0)