← back to Omega Watches 2
src/middleware.ts
51 lines
import { NextRequest, NextResponse } from "next/server";
import { verifySession, COOKIE_NAME } from "@/lib/auth";
const publicPaths = ["/login", "/api/health", "/api/auth/login"];
export async function middleware(request: NextRequest) {
const { pathname } = request.nextUrl;
// Allow public paths
if (publicPaths.some((p) => pathname.startsWith(p))) {
return NextResponse.next();
}
// Allow static assets
if (pathname.startsWith("/_next") || pathname.startsWith("/favicon")) {
return NextResponse.next();
}
// Check session
const token =
request.cookies.get(COOKIE_NAME)?.value ||
request.headers.get("authorization")?.replace("Bearer ", "");
if (!token) {
if (pathname.startsWith("/api/")) {
return NextResponse.json(
{ success: false, error: { code: "UNAUTHORIZED", message: "Login required" } },
{ status: 401 }
);
}
return NextResponse.redirect(new URL("/login", request.url));
}
const session = await verifySession(token);
if (!session) {
if (pathname.startsWith("/api/")) {
return NextResponse.json(
{ success: false, error: { code: "SESSION_EXPIRED", message: "Session expired" } },
{ status: 401 }
);
}
return NextResponse.redirect(new URL("/login", request.url));
}
return NextResponse.next();
}
export const config = {
matcher: ["/((?!_next/static|_next/image|favicon.ico).*)"],
};