fix(auth): protect root /responses rewrite

Add /responses to PUBLIC_PREFIXES in dashboardGuard so pre-rewrite remote
requests require API key validation as intended.
This commit is contained in:
Sutarto Jordan Chrisfivo
2026-09-03 09:28:56 +07:00
parent 15687d1913
commit 98579f98c1
2 changed files with 21 additions and 1 deletions

View File

@@ -34,7 +34,8 @@ const PUBLIC_API_PATHS = [
];
// Public top-level prefixes (LLM API endpoints with their own API key auth).
const PUBLIC_PREFIXES = ["/v1", "/v1beta", "/api/v1", "/api/v1beta", "/codex"];
// Keep root-level rewrites here too: middleware runs before Next.js rewrites.
const PUBLIC_PREFIXES = ["/v1", "/v1beta", "/api/v1", "/api/v1beta", "/codex", "/responses"];
// Always require JWT token regardless of requireLogin setting
const ALWAYS_PROTECTED = [