Initial implementation of TriggerShell
A Python CLI (typer) that bootstraps Node/pnpm and launches a Next.js 16 web app for running configured shell scripts: YAML config validated by a shared Zod schema, dynamic per-script forms mapped to shadcn controls, argv-safe execa execution with live WebSocket streaming, SQLite/Drizzle run history, and optional argon2 session + API token auth. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,54 @@
|
||||
import { NextResponse } from "next/server";
|
||||
import type { NextRequest } from "next/server";
|
||||
import { getConfig } from "@/lib/config/load";
|
||||
import { verifySessionCookieValue } from "@/lib/auth/session";
|
||||
|
||||
const PUBLIC_PATHS = [
|
||||
"/login",
|
||||
"/api/auth/login",
|
||||
"/api/auth/session",
|
||||
"/api/healthz",
|
||||
];
|
||||
|
||||
/** Optimistic (cookie-only) check - centralizes redirect logic per the Next.js Proxy guidance.
|
||||
* Every Route Handler also calls `requireAuth()` itself as the real, defense-in-depth check. */
|
||||
export async function proxy(request: NextRequest) {
|
||||
const { config } = getConfig();
|
||||
if (!config.auth.enabled) return NextResponse.next();
|
||||
|
||||
const { pathname } = request.nextUrl;
|
||||
if (
|
||||
PUBLIC_PATHS.some(
|
||||
(path) => pathname === path || pathname.startsWith("/_next"),
|
||||
)
|
||||
) {
|
||||
return NextResponse.next();
|
||||
}
|
||||
|
||||
const isApiRoute = pathname.startsWith("/api/");
|
||||
|
||||
if (isApiRoute) {
|
||||
// Token-authed API clients won't have a session cookie; let the route handler's requireAuth()
|
||||
// do the real check instead of rejecting here.
|
||||
if (request.headers.get("authorization")?.startsWith("Bearer "))
|
||||
return NextResponse.next();
|
||||
}
|
||||
|
||||
const sealed = request.cookies.get("triggershell_session")?.value;
|
||||
const session = await verifySessionCookieValue(sealed);
|
||||
|
||||
if (!session?.userId) {
|
||||
if (isApiRoute) {
|
||||
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
const loginUrl = new URL("/login", request.url);
|
||||
loginUrl.searchParams.set("next", pathname);
|
||||
return NextResponse.redirect(loginUrl);
|
||||
}
|
||||
|
||||
return NextResponse.next();
|
||||
}
|
||||
|
||||
export const config = {
|
||||
matcher: ["/((?!_next/static|_next/image|favicon.ico).*)"],
|
||||
};
|
||||
Reference in New Issue
Block a user