Skip to content

fix(auth): protect /settings route with middleware and update matcher (#515) - #529

Open
lmduy2612 wants to merge 1 commit into
ChainLearnOfficial:mainfrom
lmduy2612:fix/middleware-protect-settings-515
Open

lmduy2612 wants to merge 1 commit into
ChainLearnOfficial:mainfrom
lmduy2612:fix/middleware-protect-settings-515

Conversation

@lmduy2612

Copy link
Copy Markdown

Summary

Closes #515.

Ensures the /settings route is properly guarded at the Edge middleware level, preventing unauthenticated access or UI flash before client-side session checks complete.

Changes Made

  • Added "/settings" to PROTECTED_PREFIXES in src/middleware.ts.
  • Added "/settings/:path*" to the matcher configuration array in src/middleware.ts.
  • Updated unit tests in src/middleware.test.ts verifying that unauthenticated visits to /settings redirect to /connect?redirect=/settings, authenticated visits pass through, and the route matcher covers /settings/:path*.

Acceptance Criteria

  • Add /settings to PROTECTED_PREFIXES
  • Add /settings/:path* to the matcher array
  • Unauthenticated users visiting /settings are redirected to /connect?redirect=/settings
  • Authenticated users can access /settings normally

@netlify

netlify Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

❌ Deploy Preview for chainlearn failed.

Name Link
🔨 Latest commit fe07a14
🔍 Latest deploy log https://app.netlify.com/projects/chainlearn/deploys/6abf72308e67f00008de139c

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

/settings route is not protected by middleware

1 participant