Flatten the repo: move everything out of app/ to the root
Now that the CLI and the Next.js app are one package, nesting it inside app/ served no purpose - the repo root itself becomes the published npm package. Merges app/.gitignore and app/README.md into the root versions, drops the now-duplicate app/LICENSE, and updates path references (README, docs/ARCHITECTURE.md, docs/CONFIG_REFERENCE.md, package.json's repository.directory) that assumed the app/ nesting. Also fixes a real bug this surfaced: the in-app docs viewer resolved docs/ relative to process.cwd(), which only worked by accident when the CLI happened to be invoked from app/'s parent directory. A first attempt at fixing it with import.meta.dirname broke instead, for the same cross-module-graph reason config-path resolution already documented - Next compiles Route Handlers through a separate module graph that doesn't preserve source-relative import.meta paths. Fixed by exposing the app root via TRIGGERSHELL_APP_ROOT (set once in server.ts, where import.meta *does* resolve correctly), the same pattern already used for TRIGGERSHELL_CONFIG_PATH. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,54 @@
|
||||
import { NextResponse } from "next/server";
|
||||
import type { NextRequest } from "next/server";
|
||||
import { getConfig } from "@/lib/config/load";
|
||||
import { verifySessionCookieValue } from "@/lib/auth/session";
|
||||
|
||||
const PUBLIC_PATHS = [
|
||||
"/login",
|
||||
"/api/auth/login",
|
||||
"/api/auth/session",
|
||||
"/api/healthz",
|
||||
];
|
||||
|
||||
/** Optimistic (cookie-only) check - centralizes redirect logic per the Next.js Proxy guidance.
|
||||
* Every Route Handler also calls `requireAuth()` itself as the real, defense-in-depth check. */
|
||||
export async function proxy(request: NextRequest) {
|
||||
const { config } = getConfig();
|
||||
if (!config.auth.enabled) return NextResponse.next();
|
||||
|
||||
const { pathname } = request.nextUrl;
|
||||
if (
|
||||
PUBLIC_PATHS.some(
|
||||
(path) => pathname === path || pathname.startsWith("/_next"),
|
||||
)
|
||||
) {
|
||||
return NextResponse.next();
|
||||
}
|
||||
|
||||
const isApiRoute = pathname.startsWith("/api/");
|
||||
|
||||
if (isApiRoute) {
|
||||
// Token-authed API clients won't have a session cookie; let the route handler's requireAuth()
|
||||
// do the real check instead of rejecting here.
|
||||
if (request.headers.get("authorization")?.startsWith("Bearer "))
|
||||
return NextResponse.next();
|
||||
}
|
||||
|
||||
const sealed = request.cookies.get("triggershell_session")?.value;
|
||||
const session = await verifySessionCookieValue(sealed);
|
||||
|
||||
if (!session?.userId) {
|
||||
if (isApiRoute) {
|
||||
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
const loginUrl = new URL("/login", request.url);
|
||||
loginUrl.searchParams.set("next", pathname);
|
||||
return NextResponse.redirect(loginUrl);
|
||||
}
|
||||
|
||||
return NextResponse.next();
|
||||
}
|
||||
|
||||
export const config = {
|
||||
matcher: ["/((?!_next/static|_next/image|favicon.ico).*)"],
|
||||
};
|
||||
Reference in New Issue
Block a user