cwa-auth / cwa-admin middleware: behaviour with a cross-origin API, and /_cwa pages now use cwa-admin
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 72/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- nuxt
- Domain
- documentation
Research direction
Start in the middleware section covering definePageMeta({ middleware: 'cwa-auth' | 'cwa-admin' }) and review the existing guidance for pages under /_cwa. Document the same-origin and cross-origin behavior, including browser-side redirects and the brief server-rendered shell on cross-origin setups. Done means the section explains that admin pages need no extra configuration and that API data remains protected.
Written by the indexing model from the issue text.
Description
Source: cwa-nuxt-module 5be5b635 and dd4f8a6d (after 2.0.0-alpha.3).
What changed
- Every
/_cwaadmin page is guarded bycwa-admin. A signed-in non-admin is sent home. A signed-out visitor is sent to login, with?redirect=back to the page. cwa-authandcwa-adminno longer redirect on the server when they can't see a session.- With the API on a different origin, its auth cookie belongs to the API's host and never reaches the Nuxt server. The server render therefore sees every visitor as signed out, including a signed-in admin.
- Redirecting there would send a signed-in admin to login on every full page load. Instead the browser decides: Nuxt re-runs route middleware during hydration, and the browser's own cookie reaches the API.
- A signed-in non-admin is still redirected on the server, because the server knows who they are.
To document
- In the middleware section (
definePageMeta({ middleware: 'cwa-auth' | 'cwa-admin' })): on a same-origin setup (one host, as the template does) the server sees the session. On a cross-origin setup the signed-out redirect happens in the browser, so the server-rendered page shell reaches the visitor briefly. Page data is still protected, because the API refuses it. - Admin pages under
/_cwaneed no extra configuration.
- Dominant language
- Vue
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from components-web-app/docs
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
components-web-app/docs#1 · 2 comments ·
All issues in components-web-app/docs
Similar issues
-
sync-en
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
ACK_WAITING HELP_WANTED UPDATE_CS
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
OWASP/CheatSheetSeries#2458 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
l3montree-dev/devguard#3101 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
area/documentation status/need-triage
Difficulty 1/5 Under an hour Newbie friendliness 95/100
google-gemini/gemini-cli#29548 ·
Maintainers usually reply within 1 day