fix(pwa): exclude manifest.webmanifest from auth middleware (#1078)
The middleware matcher excluded the legacy manifest.json path, but the app serves its manifest from app/manifest.ts at /manifest.webmanifest. Browsers fetch manifests without credentials, so every manifest request hit the auth gate and 307-redirected to /login, making the PWA uninstallable for all users (logged in or not). Verified locally: /manifest.webmanifest returns 200 JSON, /dashboard still redirects to /login. Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -18,6 +18,6 @@ export const config = {
|
||||
* (AAL2) gate on cookie-authenticated API calls (updateSession short-
|
||||
* circuits API routes after that check: see lib/supabase/middleware.ts).
|
||||
*/
|
||||
'/((?!_next/static|_next/image|favicon.ico|\\.well-known|sw\\.js|sw-register\\.js|manifest\\.json|icons/|.*\\.(?:svg|png|jpg|jpeg|gif|webp|ico|js|json)$).*)',
|
||||
'/((?!_next/static|_next/image|favicon.ico|\\.well-known|sw\\.js|sw-register\\.js|manifest\\.json|manifest\\.webmanifest|icons/|.*\\.(?:svg|png|jpg|jpeg|gif|webp|ico|js|json)$).*)',
|
||||
],
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user