Add consistent API request logging and a themed 404 page, bump to 0.4.0
CI / Build and push image (push) Successful in 1m10s
CI / Static checks (push) Successful in 1m39s

Every app/api route handler now goes through withRouteLogging, which logs
a correlated reqId/method/path/status/duration for each request and turns
any uncaught error into a logged stack trace plus a clean JSON 500 instead
of Next's default opaque failure. proxy.ts logs rejected auth attempts, and
instrumentation.ts's onRequestError catches anything that still escapes a
route handler. Also adds a minimal not-found page matching the app's card
styling.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-26 08:45:15 +02:00
co-authored by Claude Sonnet 5
parent 5484d3cefe
commit 9e0380ec75
20 changed files with 267 additions and 109 deletions
+7 -2
View File
@@ -3,21 +3,26 @@ import { z } from "zod";
import { getEnv } from "@/lib/env";
import { timingSafeStringEqual } from "@/lib/auth/timing-safe-compare";
import { createSessionToken, sessionCookieOptions } from "@/lib/auth/session";
import { withRouteLogging } from "@/lib/api/with-route-logging";
import { createLogger } from "@/lib/logger";
const log = createLogger("auth");
const bodySchema = z.object({ secret: z.string().min(1) });
export async function POST(req: Request) {
export const POST = withRouteLogging("auth.login", async (req: Request) => {
const parsed = bodySchema.safeParse(await req.json().catch(() => null));
if (!parsed.success) {
return NextResponse.json({ error: "secret is required" }, { status: 400 });
}
if (!timingSafeStringEqual(parsed.data.secret, getEnv().ACCESS_PASSWORD)) {
log.warn("login attempt with invalid secret");
return NextResponse.json({ error: "invalid secret" }, { status: 401 });
}
log.info("login succeeded");
const token = await createSessionToken();
const res = NextResponse.json({ ok: true });
res.cookies.set({ ...sessionCookieOptions, value: token });
return res;
}
});
+3 -2
View File
@@ -1,8 +1,9 @@
import { NextResponse } from "next/server";
import { SESSION_COOKIE_NAME } from "@/lib/auth/session";
import { withRouteLogging } from "@/lib/api/with-route-logging";
export async function POST() {
export const POST = withRouteLogging("auth.logout", async () => {
const res = NextResponse.json({ ok: true });
res.cookies.delete(SESSION_COOKIE_NAME);
return res;
}
});