improvement: account setting added to header in order to choose organizations/subscribtions/etc
This commit is contained in:
@@ -3,7 +3,6 @@ import { NextResponse } from 'next/server';
|
||||
import type { NextRequest } from 'next/server';
|
||||
|
||||
const publicRoutes = ['/', '/login', '/register', '/terms', '/privacy', '/forgot-password'];
|
||||
const authOnlyRoutes = ['/login', '/register']; // routes that should NOT be accessed when logged in
|
||||
|
||||
export function middleware(request: NextRequest) {
|
||||
const { pathname } = request.nextUrl;
|
||||
@@ -15,12 +14,10 @@ export function middleware(request: NextRequest) {
|
||||
return NextResponse.redirect(new URL('/today', request.url));
|
||||
}
|
||||
|
||||
// Always allow public routes first
|
||||
// Always allow public routes first. We intentionally do not block /login or /register
|
||||
// when a cookie exists, because the cookie might be stale/invalid and the client
|
||||
// auth check needs to recover gracefully.
|
||||
if (publicRoutes.includes(pathname)) {
|
||||
// If user is already logged in and tries to access login/register → redirect to dashboard
|
||||
if (isAuthenticated && authOnlyRoutes.includes(pathname)) {
|
||||
return NextResponse.redirect(new URL('/today', request.url));
|
||||
}
|
||||
return NextResponse.next();
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user