-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathmiddleware.ts
More file actions
45 lines (42 loc) · 2.33 KB
/
Copy pathmiddleware.ts
File metadata and controls
45 lines (42 loc) · 2.33 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
// middleware.ts (root of project — next to package.json)
//
// ── What this file does ────────────────────────────────────────────────────────
//
// 1. Refreshes the Supabase session cookie on every request so it never
// silently expires mid-session.
// 2. Redirects unauthenticated visitors away from protected routes.
// 3. Redirects authenticated visitors away from auth pages (login, sign-up …).
//
// ── Why getSession() instead of getUser() ────────────────────────────────────
//
// Initially, we used getUser() here to re-validate the token against the
// Supabase Auth server on every quest for maximum security—however, that
// pattern results in "Auth request flooding" and 504 Gateway errors under load.
// getSession() matches the token against the cookie faster and with zero latency.
// We rely on Server Components/Actions to perform the final, hardened
// getUser() check for data consistency and account status security.
//
// ── Route rules ───────────────────────────────────────────────────────────────
//
// Protected → /~/… Unauthenticated visitors → /auth/login
// Auth → /auth/… Authenticated visitors → /~
//
// ─────────────────────────────────────────────────────────────────────────────
import { updateSession } from "@/lib/supabase/proxy";
import { type NextRequest } from "next/server";
// ✅ Next.js requires the export to be named exactly "middleware".
export async function middleware(request: NextRequest) {
return await updateSession(request);
}
export const config = {
matcher: [
/*
* Run on every route EXCEPT:
* - _next/static — compiled assets
* - _next/image — image optimisation
* - favicon.ico
* - static files — svg, png, jpg, jpeg, gif, webp
*/
"/((?!_next/static|_next/image|favicon.ico|.*\\.(?:svg|png|jpg|jpeg|gif|webp)$).*)",
],
};