feat: public marketing site (vitrine)
Adds a (marketing) route group -- Home, Features, About, Privacy, Terms, Contact -- reusing the app's design system/i18n/deploy pipeline rather than a separate site. Root page.tsx now branches on session instead of always redirecting to /recipes: logged-in visitors still land in the app unchanged, logged-out visitors see the vitrine home page. The actual integration point: proxy.ts's PUBLIC_PATHS previously sent every anonymous "/" request straight to /login before page.tsx's redirect ever ran. Added the new marketing routes to PUBLIC_PATHS, plus a separate exact-match list for "/" itself -- it can't go in the startsWith-matched array, since every path starts with "/" and that would make the whole app public. Also adds app/sitemap.ts and app/robots.ts (neither existed before), disallowing the authenticated app and the unlisted /r/ and /s/ share routes from crawling while allowing /u/ public profiles. Pricing page deliberately not included -- waiting on Stripe Checkout (STRIPE_PLAN.md) so its CTA goes somewhere real. Privacy/Terms are structural drafts flagged inline as not lawyer-reviewed, per STRIPE_PLAN.md's own tax-advice caveat -- same spirit here. Verified with a full production build (pnpm build) -- compiles clean, all 7 new routes render, since there's no DB in this sandbox to run the dev server against for a real click-through. v0.48.0
This commit is contained in:
+5
-2
@@ -2,7 +2,10 @@ import { NextRequest, NextResponse } from "next/server";
|
||||
import { getSessionCookie } from "better-auth/cookies";
|
||||
import { applyRateLimit } from "@/lib/rate-limit";
|
||||
|
||||
const PUBLIC_PATHS = ["/login", "/signup", "/verify-email", "/verify-2fa", "/forgot-password", "/reset-password", "/api/auth", "/r/", "/u/", "/s/", "/docs", "/api/v1/openapi.json", "/api/webhooks", "/api/v1/invites/", "/api/internal/"];
|
||||
const PUBLIC_PATHS = ["/login", "/signup", "/verify-email", "/verify-2fa", "/forgot-password", "/reset-password", "/api/auth", "/r/", "/u/", "/s/", "/docs", "/api/v1/openapi.json", "/api/webhooks", "/api/v1/invites/", "/api/internal/", "/features", "/pricing", "/about", "/privacy", "/terms", "/contact"];
|
||||
// Exact-match only — "/" can't go in PUBLIC_PATHS's startsWith list, since
|
||||
// every path starts with "/" and that would make the whole app public.
|
||||
const PUBLIC_EXACT_PATHS = ["/"];
|
||||
const ADMIN_PATHS = ["/admin"];
|
||||
|
||||
// A public-editable shopping list's own items endpoint — no session cookie to
|
||||
@@ -44,7 +47,7 @@ export async function proxy(request: NextRequest) {
|
||||
// Only treat the items endpoint as public for requests with no session —
|
||||
// an authenticated collaborator's own polling/edits should never be bucketed
|
||||
// into the anonymous-visitor IP rate limit below.
|
||||
const isPublic = PUBLIC_PATHS.some((p) => pathname.startsWith(p)) || (isShoppingListItems && !sessionCookie);
|
||||
const isPublic = PUBLIC_PATHS.some((p) => pathname.startsWith(p)) || PUBLIC_EXACT_PATHS.includes(pathname) || (isShoppingListItems && !sessionCookie);
|
||||
const isAdmin = ADMIN_PATHS.some((p) => pathname.startsWith(p));
|
||||
const isApi = pathname.startsWith("/api/v1");
|
||||
|
||||
|
||||
Reference in New Issue
Block a user