eed57cd10b
proxy.ts required a session cookie for every non-public /api/v1/* request, rejecting with 401 before the request ever reached requireSessionOrApiKey (lib/api-auth.ts) — the only place that actually verifies a Bearer API key and updates lastUsedAt. Pure API-key clients never send a session cookie, so every single API-key request was blocked at the middleware layer; the lastUsedAt update code was correct but unreachable. Now lets requests with an `Authorization: Bearer ek_...` header through to the route, which still does the real verification (and 401s itself on an invalid/unknown key) — middleware just stops pre-emptively rejecting valid ones. Also added error logging to the fire-and-forget lastUsedAt update, previously silent on failure. Verified locally: hashed a raw key, confirmed it matched the stored hash (so the lookup itself was never the problem), reproduced the 401 against the unpatched middleware, then confirmed both the 200 response and lastUsedAt populating correctly after the fix — visible in the real Settings → API Keys UI.
This is a Next.js project bootstrapped with create-next-app.
Getting Started
First, run the development server:
npm run dev
# or
yarn dev
# or
pnpm dev
# or
bun dev
Open http://localhost:3000 with your browser to see the result.
You can start editing the page by modifying app/page.tsx. The page auto-updates as you edit the file.
This project uses next/font to automatically optimize and load Geist, a new font family for Vercel.
Learn More
To learn more about Next.js, take a look at the following resources:
- Next.js Documentation - learn about Next.js features and API.
- Learn Next.js - an interactive Next.js tutorial.
You can check out the Next.js GitHub repository - your feedback and contributions are welcome!
Deploy on Vercel
The easiest way to deploy your Next.js app is to use the Vercel Platform from the creators of Next.js.
Check out our Next.js deployment documentation for more details.