mirror of
https://github.com/open-reception/appointment-booking-software.git
synced 2026-09-29 04:04:51 +02:00
Fix expired access token: Do not check access token for public routes
This commit is contained in:
@@ -38,7 +38,7 @@
|
||||
</div>
|
||||
</div>
|
||||
{:then tenant}
|
||||
{#if tenant && tenant.longName}
|
||||
{#if tenant && tenant.setupState === "READY"}
|
||||
<div class="flex max-w-(--max-w-sm) flex-col justify-between gap-3">
|
||||
{#if typeof tenant.logo === "string" && tenant.logo}
|
||||
<img
|
||||
@@ -49,13 +49,13 @@
|
||||
/>
|
||||
{/if}
|
||||
<div class="flex flex-col items-start gap-1">
|
||||
<Headline level="h1" style="h4">{tenant?.longName}</Headline>
|
||||
<Headline level="h1" style="h4">{tenant.longName}</Headline>
|
||||
<Text style="md" color="medium" class="whitespace-pre-line">
|
||||
<LocalizedText translations={tenant.descriptions} />
|
||||
</Text>
|
||||
{#if tenant?.links.website}
|
||||
{#if tenant.links.website}
|
||||
<Button
|
||||
href={tenant?.links.website}
|
||||
href={tenant.links.website}
|
||||
variant="link"
|
||||
class="mt-1 h-auto w-auto self-start"
|
||||
target="_blank"
|
||||
@@ -80,7 +80,7 @@
|
||||
{#await data.streaming.tenant}
|
||||
<Skeleton class="h-10 w-full" />
|
||||
{:then tenant}
|
||||
{#if tenant?.setupState === "READY" && tenant.longName}
|
||||
{#if tenant?.setupState === "READY"}
|
||||
<Button size="lg" class="w-full" href={ROUTES.BOOK_APPOINTMENT}>
|
||||
{m["public.bookAppointment"]()}
|
||||
</Button>
|
||||
|
||||
@@ -12,6 +12,15 @@ const GLOBAL_ADMIN_PATHS = ["/api/admin"];
|
||||
export const apiAuthHandle: Handle = async ({ event, resolve }) => {
|
||||
const { url } = event;
|
||||
const path = url.pathname;
|
||||
|
||||
// Public api paths should be available without authentication
|
||||
const whitelist = ["/api/public"];
|
||||
const skip = whitelist.some((wlPath) => path.startsWith(wlPath));
|
||||
if (skip) {
|
||||
return resolve(event);
|
||||
}
|
||||
|
||||
// Front-End routes are not handled here
|
||||
if (!path.startsWith("/api")) {
|
||||
return resolve(event);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user