-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathmiddleware.ts
More file actions
72 lines (61 loc) · 1.94 KB
/
Copy pathmiddleware.ts
File metadata and controls
72 lines (61 loc) · 1.94 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
import NextAuth from "next-auth";
import authConfig from "./auth.config";
import {
DEFAULT_LOGIN_REDIRECT,
adminPrefix,
allUserAcessRoute,
apiAuthPrefix,
authRoutes,
publicRoutes,
} from "./routes";
import arcjet, { createMiddleware, detectBot } from "@arcjet/next";
const { auth } = NextAuth(authConfig);
export default auth(async (req) => {
const { nextUrl } = req;
const isLoggedIn = !!req.auth;
// console.log("Authentication is enabled for " + req.auth?.user.status);
const isBanned = req.auth?.user.status === "BANNED";
const isAdmin = req.auth?.user.role === "ADMIN";
const isAdminRoute = nextUrl.pathname.startsWith(adminPrefix);
const isApiAuthRoute = nextUrl.pathname.startsWith(apiAuthPrefix);
const isPublicRoutes = publicRoutes.includes(nextUrl.pathname);
const isAuthRoute = authRoutes.includes(nextUrl.pathname);
const isAllAccessRoute = allUserAcessRoute.includes(nextUrl.pathname);
if (isApiAuthRoute) {
return;
}
if (isBanned) {
req.auth = null;
return Response.redirect(new URL("/auth/login", nextUrl));
}
if (isAuthRoute) {
if (isLoggedIn) {
return Response.redirect(new URL(DEFAULT_LOGIN_REDIRECT, nextUrl));
}
return;
}
if (isLoggedIn) {
if (isAllAccessRoute) {
return;
}
if (!isAdmin && isAdminRoute) {
return Response.redirect(new URL(DEFAULT_LOGIN_REDIRECT, nextUrl));
}
if (isAdmin && !isAdminRoute) {
return Response.redirect(new URL("/admin", nextUrl));
}
}
if (!isLoggedIn && !isPublicRoutes) {
return Response.redirect(new URL("/auth/login", nextUrl));
}
return;
});
export const config = {
matcher: [
// Exclude files with a "." followed by an extension, which are typically static files.
// Exclude files in the _next directory, which are Next.js internals.
"/((?!.+\\.[\\w]+$|_next).*)",
// Re-include any files in the api or trpc folders that might have an extension
"/(api|trpc)(.*)",
],
};