forked from jmarioste/nextjs-role-based-auth-tutorial
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathmiddleware.ts
22 lines (22 loc) · 807 Bytes
/
middleware.ts
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
import { getToken } from "next-auth/jwt";
import { NextFetchEvent, NextRequest, NextResponse } from "next/server";
export async function middleware(request: NextRequest, _next: NextFetchEvent) {
const { pathname } = request.nextUrl;
const protectedPaths = ["/admin"];
const matchesProtectedPath = protectedPaths.some((path) =>
pathname.startsWith(path)
);
if (matchesProtectedPath) {
const token = await getToken({ req: request });
if (!token) {
const url = new URL(`/api/auth/signin`, request.url);
url.searchParams.set("callbackUrl ", encodeURI(request.url));
return NextResponse.redirect(url);
}
if (token.role !== "admin") {
const url = new URL(`/403`, request.url);
return NextResponse.rewrite(url);
}
}
return NextResponse.next();
}