fix(control): allow login when HTTP server is stopped
Mount auth routes on the control plane and proxy /api/auth to :8600 in dev:pm2 so the UI can authenticate while the HTTP API process is down. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -18,6 +18,24 @@ export function cookieOpts() {
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* Require JWT for /api routes except bootstrap, login, and register.
|
||||
* @param {import("fastify").FastifyInstance} api
|
||||
* @param {import("fastify").FastifyInstance} root
|
||||
*/
|
||||
export function addApiAuthGuard(api, root) {
|
||||
api.addHook("onRequest", async (req, reply) => {
|
||||
const raw = (req.url || "").split("?")[0];
|
||||
const stripped = raw.replace(/^\/api/, "") || "/";
|
||||
const routeUrl = req.routeOptions?.url || stripped;
|
||||
const open =
|
||||
OPEN_API_ROUTES.has(`${req.method} ${routeUrl}`) ||
|
||||
OPEN_API_ROUTES.has(`${req.method} ${stripped}`);
|
||||
if (open) return;
|
||||
await root.authenticate(req, reply);
|
||||
});
|
||||
}
|
||||
|
||||
export function validateCredentials(username, password) {
|
||||
if (!/^[A-Za-z0-9_]{3,32}$/.test(username)) {
|
||||
return "username must be 3-32 letters, numbers, or underscore";
|
||||
|
||||
Reference in New Issue
Block a user