From de50bde6f980c63704bbc1ee9e23a1abd0f82a17 Mon Sep 17 00:00:00 2001 From: Jared Pereira Date: Tue, 2 Sep 2025 19:47:49 +0900 Subject: [PATCH] actually set and check auth_completed variable --- middleware.ts | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/middleware.ts b/middleware.ts index ea2fddb8..e5e782e3 100644 --- a/middleware.ts +++ b/middleware.ts @@ -60,14 +60,26 @@ export default async function middleware(req: NextRequest) { req.nextUrl.pathname.includes("/rss") || req.nextUrl.pathname.includes("/atom") || req.nextUrl.pathname.includes("/json"); + + // Check if we've already completed auth (prevents redirect loop when cookies are disabled) + let authCompleted = req.nextUrl.searchParams.has("auth_completed"); + if ( !isStaticReq && (!cookie || req.nextUrl.searchParams.has("refreshAuth")) && - !req.nextUrl.searchParams.has("auth_completed") && + !authCompleted && !hostname.includes("leaflet.pub") ) { return initiateAuthCallback(req); } + + // If auth was completed but we still don't have a cookie, cookies might be disabled + // Continue without auth rather than looping + if (authCompleted && !cookie) { + console.warn( + "Auth completed but no cookie set - cookies may be disabled", + ); + } let aturi = new AtUri(pub?.uri); return NextResponse.rewrite( new URL( @@ -156,7 +168,7 @@ async function receiveAuthCallback(req: NextRequest) { let url = new URL(token.redirect); url.searchParams.set("auth_completed", "true"); - let response = NextResponse.redirect(token.redirect); + let response = NextResponse.redirect(url.toString()); response.cookies.set("external_auth_token", token.auth_token || "null"); return response; } -- 2.51.2