Security: - requireAdmin() session check added to every admin-only server action (previously relied only on middleware path matching, which Next.js Server Actions don't reliably respect) - Real Prisma + bcrypt admin auth, replacing hardcoded credentials; split into an Edge-safe auth.config.ts (used by proxy.ts) and the full Prisma-backed auth.ts (route handler, server actions, server components) - Removed hardcoded fallback secret on the Instagram sync cron endpoint - Honeypot field + per-IP rate limiting on contact/business-submission forms and the analytics events endpoint Features: - AI trip planner (/plan-olustur, /plan/[id]) backed by DeepSeek, grounded to only recommend isLocalApproved listings, with a deterministic link-injection fallback for anything the model doesn't format as markdown - Interactive Leaflet/OpenStreetMap view on category listing pages - Telegram notifications for new contact messages and business submissions SEO: - Brand-consistent favicon/apple-icon/PWA icons and default Open Graph/ Twitter share images, generated via next/og (replacing default Next.js placeholders) - BreadcrumbList structured data on category and listing detail pages - Fixed two remaining raw <img> tags to use next/image Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
30 lines
810 B
TypeScript
30 lines
810 B
TypeScript
import type { NextAuthConfig } from "next-auth"
|
|
|
|
/**
|
|
* Edge-safe NextAuth config (no providers, no Prisma import) — used by
|
|
* proxy.ts to read the session JWT in the Edge middleware runtime, where
|
|
* @prisma/client cannot run. The Prisma-backed CredentialsProvider lives in
|
|
* lib/auth.ts and only executes in the Node.js runtime (route handler,
|
|
* server actions, server components).
|
|
*/
|
|
export const authConfig = {
|
|
pages: {
|
|
signIn: '/login'
|
|
},
|
|
callbacks: {
|
|
async jwt({ token, user }) {
|
|
if (user) {
|
|
token.role = (user as any).role
|
|
}
|
|
return token
|
|
},
|
|
async session({ session, token }) {
|
|
if (session.user && token.role) {
|
|
(session.user as any).role = token.role
|
|
}
|
|
return session
|
|
}
|
|
},
|
|
providers: [],
|
|
} satisfies NextAuthConfig
|