mirror of
https://github.com/Portabase/portabase.git
synced 2026-07-14 11:16:13 +02:00
* feat(onboarding): add cookie helper, types and mock data * feat(onboarding): add stepper, contextual preview and shell * feat(onboarding): add sso-gate step * feat(onboarding): add account-info step with real signup * feat(onboarding): add security step * feat(onboarding): add preferences step * fix(onboarding): validate avatar upload size/type and handle FileReader errors * feat(onboarding): add org-create step * feat(onboarding): add invite-members step * feat(onboarding): add notifier step reusing real provider list * feat(onboarding): add storage step reusing real provider list * feat(onboarding): add defaults step * feat(onboarding): add agent-create step * feat(onboarding): add agent-waiting step with simulated ping * feat(onboarding): add project-create step * feat(onboarding): add db-settings step with per-db repeat * feat(onboarding): add finish step with confetti * feat(onboarding): wire full step graph * feat(onboarding): add /welcome route * feat(onboarding): gate landing, auth and dashboard routes behind onboarding cookie * fix(onboarding): call next() in finish step so onFlowComplete fires and cookie is written * docs: add onboarding channel config + style refactor spec * docs: add conditional step skip when no agents to spec * docs(onboarding): add implementation plan for channel config flow and style refactor * feat(onboarding): extend OnboardingChannel with name and config fields * feat(onboarding): add two-phase config flow and org-combobox style to notifier step * fix(onboarding): prevent duplicate notifier providers and guard Continue button * feat(onboarding): add two-phase config flow and org-combobox style to storage step * style(onboarding): restyle sso-gate provider buttons to org-combobox card style * style(onboarding): restyle security method choice to org-combobox card style * style(onboarding): restyle theme toggles in preferences step to org-combobox card style * style(onboarding): restyle DB toggle buttons in project-create step to org-combobox card style * feat(onboarding): skip agent-waiting/project-create/db-settings when no agents created * feat(onboarding): update type system — meta, firstName/lastName, org.id, databases * feat(onboarding): add settings.onboarding column + markOnboardingDoneAction * feat(onboarding): add resolveOnboardingState server function * fix(onboarding): remove unused imports from onboarding-state.ts * style(onboarding): add branding to shell, fix progress bar full width * feat(onboarding): replace preview panel with stepper checklist * feat(onboarding): add step-login replacing sso-gate * fix(onboarding): step-login — conform to global mutation pattern, handle SSO errors * feat(onboarding): step-account-info — firstName/lastName, conditional password, findOrCreate * feat(onboarding): avatar API route (next/og) + AvatarPicker in preferences step * feat(onboarding): step-security reads passkeyEnabled from flowData.meta * feat(onboarding): step-org-create calls real createOrganizationAction * fix(onboarding): step-org-create — simplify error handling, throw on empty name * feat(onboarding): notifier + storage steps call real actions + findOrCreate on back * feat(onboarding): step-agent-create calls real createAgentAction + findOrCreate * feat(onboarding): step-agent-waiting polls real agent lastContact via useQuery * feat(onboarding): add step-agent-key with edgeKey generation via server action * feat(onboarding): step-project-create uses real action + real DBs from flowData * feat(onboarding): wire steps — add login + agent-key, remove sso-gate * feat(onboarding): page.tsx uses resolveOnboardingState — server-driven resume * chore(onboarding): delete mock/cookie/preview/sso-gate files — replaced by real implementation * feat(onboarding): add emailPasswordEnabled to meta, remove logoDataUrl from org * feat(onboarding): DB-driven resume — query notifiers/storages, check agent lastContact * feat(onboarding): agent-waiting step is now skippable * feat(onboarding): login — auto-advance if session, callbackURL on SSO, hide email/pw when disabled, empty state * fix(onboarding): step-login — add next to useEffect deps, default emailPasswordEnabled to false * fix(onboarding): verify session after passkey registration, fallback to signIn.passkey() * feat(onboarding): theme applied dynamically via setTheme, avatar saved to user.image * feat(onboarding): remove org logo upload — orgs have no logo * feat(onboarding): show Next button in shell when navigating backwards * docs: add onboarding refactor design spec * docs: add onboarding refactor implementation plan * refactor(onboarding): extract useCreateAgent and useDeleteAgent hooks * refactor(onboarding): extract useCreateOrg and useCreateProject hooks * fix(onboarding): trim project name, standardize error narrowing in org/project hooks * fix(onboarding): use narrowed createData.value in use-create-org * refactor(onboarding): extract useUpdateAccount hook * refactor(onboarding): extract useAddNotifier and useRemoveNotifier hooks * refactor(onboarding): extract useAddStorage and useRemoveStorage hooks * refactor(onboarding): extract useAgentStatus and useGenerateEdgeKey hooks * refactor(onboarding): extract useMarkOnboardingDone hook, remove .gitkeep files * docs: add onboarding theme persistence & progress bar fix spec * docs: add onboarding theme & progress bar implementation plan * fix(onboarding): persist theme to db on selection in StepPreferences * fix(onboarding): recalculate progress bar from full STEP_ORDER position * fix(theme): sync user theme from DB on all routes, not only dashboard * fix(theme): use current theme as fallback in preferences, prevent session override of localStorage * fix(onboarding): correct resume steps and skip agent-waiting flash when agent is connected * fix(onboarding): properly resolve onboarding state, remove redirect trap in step-defaults, block waiting flash * fix(onboarding): resume at db-settings instead of finish if no database exists for the project * fix(onboarding): redirect to agent-create if project exists but no agent is found * fix(onboarding): allow going from agent-create to project-create if a project already exists * fix(onboarding): skip intermediate agent steps when going back from project-create to agent-create * fix(onboarding): skip default step when going back from agent-create if no notifiers and storages exist * feat(onboarding): allow user to choose between passkey and password during registration if both are enabled * feat(onboarding): replace tabs with single form and multiple buttons for auth choice * style(onboarding): improve empty auth state UI with lucide icon and better layout * fix(onboarding): completely hide back button on the first step instead of disabling it * fix(onboarding): skip default step if no notifiers and storages exist when advancing from storage step * fix(onboarding): correctly show select placeholder when default value does not exist in the list * refactor(onboarding): remove duplicate generate-edge-key action and use core utility directly * feat(onboarding): compute edgeKey directly on the server side to avoid lazy loading * fix(onboarding): skip db-settings step if no database is found on the agent * fix(onboarding): do not skip db settings if agent is connected but no databases found * refactor(onboarding): skip db settings entirely if no database is selected in project create * feat(onboarding): auto-save database selections on project create instantly * style(onboarding): replace button opacity flash with specific spinner animation on db select * feat(onboarding): extend OnboardingDbSettings with retention, schedule, and policy fields * feat(onboarding): add applyOnboardingDbSettingsAction server action * feat(onboarding): add BackupScheduleSelector component * feat(onboarding): rewrite step-db-settings with three-level phase navigation and full policy persistence * fix(onboarding): wire applyMutation.mutateAsync everywhere and stabilize list keys * docs(sdd): append hotfix summary for applyMutation and list keys * fix(onboarding): address final review findings - atomicity, scheduling guard, apply-all recovery, client validation * add: onboarding * fix(migration): merge * fix(migration): apply for onboarding * fix(settings): make avatar selector, dicebear picker and tab bar responsive * chore: checkpoint before features reorganization * Task 2: Add migration script for features directory reorganization * refactor(agents): reorganize into actions/components/schemas/hooks * refactor(auth): reorganize into actions/components/schemas * refactor(channel): reorganize into components/schemas, nest notifications+storages under components * refactor(database): reorganize into actions/components/schemas * refactor(layout): move all components to components/ * refactor(logs): reorganize into components/types * refactor(migration): reorganize into actions/components * refactor(notifications): reorganize into components/types/utils * refactor(organizations): reorganize into actions/components/schemas/hooks/utils * refactor(profile): reorganize into actions/components/schemas * refactor(projects): reorganize into actions/components/schemas * refactor(settings): reorganize into actions/components/schemas/hooks * refactor(statistics): reorganize into components/utils * refactor(storages): reorganize into types/utils * refactor(theme): move all components to components/ * refactor(updates): reorganize into components/hooks * refactor(upload): move action to actions/ * refactor(users): reorganize into actions/components/schemas * fix: update broken imports after features reorganization (double-quote relative imports, channel subdir absolute paths) * fix: .gitignore * fix: onboarding * fix: removed dead files * feat: backfill onboarding flag for instances with existing data * fix: persist onboarding=true on boot when SKIP_ONBOARDING is set * feat: remove avatarMode/dicebearStyle from DB schema and types * feat: simplify resolveAvatarUrl — custom image first, gravatar fallback * feat: allow avatar upload regardless of mode * feat: remove avatarMode from layout and profile prop chains * feat: remove avatar mode admin tab and supporting files * feat: remove avatar mode selector from onboarding defaults step * fix: remove preferences onboarding step and fix routing * fix: remove stale preferences entry from onboarding checklist * feat: add avatar reset button and explanatory tooltip on profile page * fix: move avatar tooltip to top-right badge overlay on avatar * fix: use small destructive button for avatar removal * fix * Update step-defaults.tsx * fix: default dev password for keycloak refer to env * fix * fix(migration): refactoring * fix: api agent helpers.ts * Update .env.example --------- Co-authored-by: Théo LAGACHE <theo.lagache@soluce-technologies.com> Co-authored-by: charles-gauthereau <charles.gauthereau@soluce-technologies.com>
128 lines
3.9 KiB
TypeScript
128 lines
3.9 KiB
TypeScript
import { NextRequest, NextResponse } from "next/server";
|
|
import { loggingMiddleware } from "@/middleware/loggingMiddleware";
|
|
import { errorHandler } from "@/middleware/errorHandler";
|
|
import { auth } from "@/lib/auth/auth";
|
|
import { headers } from "next/headers";
|
|
import { env } from "@/env.mjs";
|
|
import { User } from "@/db/schema/02_user";
|
|
|
|
export async function proxy(request: NextRequest) {
|
|
const url = request.nextUrl.clone();
|
|
const redirectUrl = encodeURIComponent(request.nextUrl.pathname);
|
|
|
|
if (url.pathname.startsWith("/dashboard")) {
|
|
const session = await auth.api.getSession({
|
|
headers: await headers(),
|
|
});
|
|
if (!session) {
|
|
return NextResponse.redirect(
|
|
new URL(`/login?redirect=${redirectUrl}`, request.url),
|
|
);
|
|
}
|
|
const user = session.user as User;
|
|
|
|
if (user.banned) {
|
|
await auth.api.signOut({ headers: await headers() });
|
|
return NextResponse.redirect(new URL("/login?error=banned", request.url));
|
|
}
|
|
if (user.role === "pending") {
|
|
await auth.api.signOut({ headers: await headers() });
|
|
return NextResponse.redirect(
|
|
new URL(`/login?error=pending?redirect=${redirectUrl}`, request.url),
|
|
);
|
|
}
|
|
if (url.pathname === "/dashboard") {
|
|
return NextResponse.redirect(new URL(`/dashboard/home`, request.url));
|
|
}
|
|
return NextResponse.next();
|
|
}
|
|
|
|
if (url.pathname.startsWith("/api/auth")) {
|
|
return NextResponse.next();
|
|
}
|
|
|
|
if (url.pathname.startsWith("/api")) {
|
|
if (url.pathname.startsWith("/api/v1")) {
|
|
const apiEnabled = env.API_ENABLED;
|
|
if (!apiEnabled) {
|
|
return new NextResponse(
|
|
JSON.stringify({
|
|
message: "This API route does not exist.",
|
|
status: 404,
|
|
}),
|
|
{ status: 404, headers: { "Content-Type": "application/json" } },
|
|
);
|
|
}
|
|
const openapiEnabled = env.OPENAPI_ENABLED;
|
|
if (
|
|
!openapiEnabled &&
|
|
(url.pathname.startsWith("/api/v1/docs") ||
|
|
url.pathname.startsWith("/api/v1/openapi"))
|
|
) {
|
|
return new NextResponse(
|
|
JSON.stringify({
|
|
message: "This API route does not exist.",
|
|
status: 404,
|
|
}),
|
|
{ status: 404, headers: { "Content-Type": "application/json" } },
|
|
);
|
|
}
|
|
}
|
|
|
|
const routeExists = checkRouteExists(url.pathname);
|
|
if (!routeExists) {
|
|
return new NextResponse(
|
|
JSON.stringify({
|
|
message: "This API route does not exist.",
|
|
status: 404,
|
|
}),
|
|
{
|
|
status: 404,
|
|
headers: { "Content-Type": "application/json" },
|
|
},
|
|
);
|
|
}
|
|
}
|
|
try {
|
|
loggingMiddleware(request);
|
|
} catch (err) {
|
|
errorHandler(err);
|
|
}
|
|
}
|
|
|
|
function checkRouteExists(pathname: string) {
|
|
const routePatterns = [
|
|
/^\/api\/agent\/[^/]+\/status\/?$/,
|
|
/^\/api\/agent\/[^/]+\/backup\/?$/,
|
|
/^\/api\/agent\/[^/]+\/backup\/upload\/init\/?$/,
|
|
/^\/api\/agent\/[^/]+\/backup\/upload\/status\/?$/,
|
|
/^\/api\/agent\/[^/]+\/restore\/?$/,
|
|
/^\/api\/files\/images\/[^/]+\/?$/,
|
|
/^\/api\/files\/backups\/?$/,
|
|
/^\/api\/tus\/hooks\/?$/,
|
|
/^\/api\/events\/?$/,
|
|
/^\/api\/config\/?$/,
|
|
/^\/api\/health\/?$/,
|
|
/^\/api\/google\/drive\/callback\/?$/,
|
|
/^\/api\/avatar\/?$/,
|
|
// v1 external API
|
|
/^\/api\/v1\/mcp\/?$/,
|
|
/^\/api\/v1\/docs\/?$/,
|
|
/^\/api\/v1\/openapi\/?$/,
|
|
/^\/api\/v1\/agents\/?$/,
|
|
/^\/api\/v1\/agents\/[^/]+\/?$/,
|
|
/^\/api\/v1\/agents\/[^/]+\/key\/?$/,
|
|
/^\/api\/v1\/databases\/?$/,
|
|
/^\/api\/v1\/databases\/[^/]+\/?$/,
|
|
/^\/api\/v1\/databases\/[^/]+\/backup\/?$/,
|
|
/^\/api\/v1\/databases\/[^/]+\/backup\/[^/]+\/?$/,
|
|
/^\/api\/v1\/databases\/[^/]+\/restore\/?$/,
|
|
/^\/api\/v1\/databases\/[^/]+\/status\/?$/,
|
|
];
|
|
return routePatterns.some((pattern) => pattern.test(pathname));
|
|
}
|
|
|
|
export const config = {
|
|
matcher: ["/api/:path*", "/dashboard/:path*", "/dashboard"],
|
|
};
|