fix(confidence-engine): keep health endpoint public

This commit is contained in:
2026-09-09 10:01:10 +01:00
parent 896851e68d
commit f557175bfb
2 changed files with 9 additions and 1 deletions
+1 -1
View File
@@ -1,7 +1,7 @@
import { createServerClient } from "@supabase/ssr";
import { NextResponse } from "next/server";
const PUBLIC_PATHS = ["/login", "/auth"];
const PUBLIC_PATHS = ["/login", "/auth", "/api/health"];
export async function middleware(request) {
const pathname = request.nextUrl.pathname;
+8
View File
@@ -69,6 +69,14 @@ describe("authenticated product boundary", () => {
expect(mockGetAuthenticatedUser).not.toHaveBeenCalled();
});
it("does not convert /api/health to 401 via middleware when unauthenticated", async () => {
mockGetUser.mockResolvedValue({ data: { user: null } });
const { middleware } = await import("@/middleware.js");
const response = await middleware(new NextRequest("http://localhost:3000/api/health"));
expect(response.status).toBe(200);
});
it("redirects unauthenticated product access to the login surface", async () => {
mockGetUser.mockResolvedValue({ data: { user: null } });
const { middleware } = await import("@/middleware.js");