should respect __Secure, filter admin through middleware
This commit is contained in:
parent
0043a5bf3c
commit
b399af74e4
1 changed files with 2 additions and 2 deletions
|
@ -1,6 +1,6 @@
|
|||
import { NextRequest, NextResponse } from 'next/server';
|
||||
|
||||
const protectedRoutes = ['/dashboard'];
|
||||
const protectedRoutes = ['/dashboard', '/admin'];
|
||||
|
||||
export async function middleware(request: NextRequest) {
|
||||
const { pathname } = request.nextUrl;
|
||||
|
@ -13,7 +13,7 @@ export async function middleware(request: NextRequest) {
|
|||
return NextResponse.next();
|
||||
}
|
||||
|
||||
const sessionToken = request.cookies.get('better-auth.session_token')?.value;
|
||||
const sessionToken = request.cookies.get('better-auth.session_token')?.value || request.cookies.get('__Secure-better-auth.session_token')?.value;
|
||||
|
||||
if (!sessionToken) {
|
||||
const loginUrl = new URL('/login', request.url);
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue