cwa-auth / cwa-admin middleware: behaviour with a cross-origin API, and /_cwa pages now use cwa-admin
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 72/100
- issue の種類
- ドキュメント
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 技術スタック
- nuxt
調査の方向性
Start in the middleware section covering definePageMeta({ middleware: 'cwa-auth' | 'cwa-admin' }) and review the existing guidance for pages under /_cwa. Document the same-origin and cross-origin behavior, including browser-side redirects and the brief server-rendered shell on cross-origin setups. Done means the section explains that admin pages need no extra configuration and that API data remains protected.
索引モデルが issue の本文から書いたものです。
説明
Source: cwa-nuxt-module 5be5b635 and dd4f8a6d (after 2.0.0-alpha.3).
What changed
- Every
/_cwaadmin page is guarded bycwa-admin. A signed-in non-admin is sent home. A signed-out visitor is sent to login, with?redirect=back to the page. cwa-authandcwa-adminno longer redirect on the server when they can't see a session.- With the API on a different origin, its auth cookie belongs to the API's host and never reaches the Nuxt server. The server render therefore sees every visitor as signed out, including a signed-in admin.
- Redirecting there would send a signed-in admin to login on every full page load. Instead the browser decides: Nuxt re-runs route middleware during hydration, and the browser's own cookie reaches the API.
- A signed-in non-admin is still redirected on the server, because the server knows who they are.
To document
- In the middleware section (
definePageMeta({ middleware: 'cwa-auth' | 'cwa-admin' })): on a same-origin setup (one host, as the template does) the server sees the session. On a cross-origin setup the signed-out redirect happens in the browser, so the server-rendered page shell reaches the visitor briefly. Page data is still protected, because the API refuses it. - Admin pages under
/_cwaneed no extra configuration.
- 主要言語
- Vue
- スター
- 0
- フォーク
- 0
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
components-web-app/docs のほかの issue
-
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
components-web-app/docs#1 · コメント 2 件 ·
components-web-app/docs の issue をすべて見る
似ている issue
-
area:breg criticality:p3 documentation triage:needs-implementation
難易度 1/5 1時間未満 初心者へのやさしさ 86/100
registrystack/registry-stack#1713 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
posit-dev/ggsql#565 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
-
documentation easy good first issue help wanted
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
lacs-project/sysknife#518 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
qgis/QGIS-Plugins-Website#459 ·
-
bot-found documentation priority: P3
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
madenvel/KalinkaPlayer#178 ·