Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

cwa-auth / cwa-admin middleware: behaviour with a cross-origin API, and /_cwa pages now use cwa-admin

Abierto Apto para principiantes
#119 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
72/100
Tipo de issue
Documentación
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
nuxt

Línea de trabajo

Start in the middleware section covering definePageMeta({ middleware: 'cwa-auth' | 'cwa-admin' }) and review the existing guidance for pages under /_cwa. Document the same-origin and cross-origin behavior, including browser-side redirects and the brief server-rendered shell on cross-origin setups. Done means the section explains that admin pages need no extra configuration and that API data remains protected.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

documentation

Source: cwa-nuxt-module 5be5b635 and dd4f8a6d (after 2.0.0-alpha.3).

What changed

  • Every /_cwa admin page is guarded by cwa-admin. A signed-in non-admin is sent home. A signed-out visitor is sent to login, with ?redirect= back to the page.
  • cwa-auth and cwa-admin no longer redirect on the server when they can't see a session.
    • With the API on a different origin, its auth cookie belongs to the API's host and never reaches the Nuxt server. The server render therefore sees every visitor as signed out, including a signed-in admin.
    • Redirecting there would send a signed-in admin to login on every full page load. Instead the browser decides: Nuxt re-runs route middleware during hydration, and the browser's own cookie reaches the API.
    • A signed-in non-admin is still redirected on the server, because the server knows who they are.

To document

  • In the middleware section (definePageMeta({ middleware: 'cwa-auth' | 'cwa-admin' })): on a same-origin setup (one host, as the template does) the server sees the session. On a cross-origin setup the signed-out redirect happens in the browser, so the server-rendered page shell reaches the visitor briefly. Page data is still protected, because the API refuses it.
  • Admin pages under /_cwa need no extra configuration.
Lenguaje dominante
Vue
Estrellas
0
Forks
0
Métricas de merge de PR
Sin PR fusionados en 30 d

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de components-web-app/docs

Todos los issues de components-web-app/docs

Issues similares

Más issues de Documentation

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.