Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

cwa-auth / cwa-admin middleware: behaviour with a cross-origin API, and /_cwa pages now use cwa-admin

Open Beginner friendly
#119 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
72/100
Issue type
Documentation
Clarity
Mostly clear
Activity status
Active
Tech stack
nuxt
Domain
documentation

Research direction

Start in the middleware section covering definePageMeta({ middleware: 'cwa-auth' | 'cwa-admin' }) and review the existing guidance for pages under /_cwa. Document the same-origin and cross-origin behavior, including browser-side redirects and the brief server-rendered shell on cross-origin setups. Done means the section explains that admin pages need no extra configuration and that API data remains protected.

Written by the indexing model from the issue text.

Description

documentation

Source: cwa-nuxt-module 5be5b635 and dd4f8a6d (after 2.0.0-alpha.3).

What changed

  • Every /_cwa admin page is guarded by cwa-admin. A signed-in non-admin is sent home. A signed-out visitor is sent to login, with ?redirect= back to the page.
  • cwa-auth and cwa-admin no longer redirect on the server when they can't see a session.
    • With the API on a different origin, its auth cookie belongs to the API's host and never reaches the Nuxt server. The server render therefore sees every visitor as signed out, including a signed-in admin.
    • Redirecting there would send a signed-in admin to login on every full page load. Instead the browser decides: Nuxt re-runs route middleware during hydration, and the browser's own cookie reaches the API.
    • A signed-in non-admin is still redirected on the server, because the server knows who they are.

To document

  • In the middleware section (definePageMeta({ middleware: 'cwa-auth' | 'cwa-admin' })): on a same-origin setup (one host, as the template does) the server sees the session. On a cross-origin setup the signed-out redirect happens in the browser, so the server-rendered page shell reaches the visitor briefly. Page data is still protected, because the API refuses it.
  • Admin pages under /_cwa need no extra configuration.
Dominant language
Vue
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from components-web-app/docs

All issues in components-web-app/docs

Similar issues

More Documentation issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.