fix(pwa): exclude manifest.webmanifest from auth middleware (#1078)

The middleware matcher excluded the legacy manifest.json path, but the
app serves its manifest from app/manifest.ts at /manifest.webmanifest.
Browsers fetch manifests without credentials, so every manifest request
hit the auth gate and 307-redirected to /login, making the PWA
uninstallable for all users (logged in or not).

Verified locally: /manifest.webmanifest returns 200 JSON, /dashboard
still redirects to /login.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-07-20 13:37:26 +02:00
committed by GitHub
parent d88141dc00
commit 0fbb0f8fa8
+1 -1
View File
@@ -18,6 +18,6 @@ export const config = {
* (AAL2) gate on cookie-authenticated API calls (updateSession short-
* circuits API routes after that check: see lib/supabase/middleware.ts).
*/
'/((?!_next/static|_next/image|favicon.ico|\\.well-known|sw\\.js|sw-register\\.js|manifest\\.json|icons/|.*\\.(?:svg|png|jpg|jpeg|gif|webp|ico|js|json)$).*)',
'/((?!_next/static|_next/image|favicon.ico|\\.well-known|sw\\.js|sw-register\\.js|manifest\\.json|manifest\\.webmanifest|icons/|.*\\.(?:svg|png|jpg|jpeg|gif|webp|ico|js|json)$).*)',
],
}