Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

cwa-auth / cwa-admin middleware: behaviour with a cross-origin API, and /_cwa pages now use cwa-admin

オープン 初心者向け
#119 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
72/100
issue の種類
ドキュメント
明瞭さ
おおむね明確
活発さ
活発
技術スタック
nuxt
領域
documentation

調査の方向性

Start in the middleware section covering definePageMeta({ middleware: 'cwa-auth' | 'cwa-admin' }) and review the existing guidance for pages under /_cwa. Document the same-origin and cross-origin behavior, including browser-side redirects and the brief server-rendered shell on cross-origin setups. Done means the section explains that admin pages need no extra configuration and that API data remains protected.

索引モデルが issue の本文から書いたものです。

説明

documentation

Source: cwa-nuxt-module 5be5b635 and dd4f8a6d (after 2.0.0-alpha.3).

What changed

  • Every /_cwa admin page is guarded by cwa-admin. A signed-in non-admin is sent home. A signed-out visitor is sent to login, with ?redirect= back to the page.
  • cwa-auth and cwa-admin no longer redirect on the server when they can't see a session.
    • With the API on a different origin, its auth cookie belongs to the API's host and never reaches the Nuxt server. The server render therefore sees every visitor as signed out, including a signed-in admin.
    • Redirecting there would send a signed-in admin to login on every full page load. Instead the browser decides: Nuxt re-runs route middleware during hydration, and the browser's own cookie reaches the API.
    • A signed-in non-admin is still redirected on the server, because the server knows who they are.

To document

  • In the middleware section (definePageMeta({ middleware: 'cwa-auth' | 'cwa-admin' })): on a same-origin setup (one host, as the template does) the server sees the session. On a cross-origin setup the signed-out redirect happens in the browser, so the server-rendered page shell reaches the visitor briefly. Page data is still protected, because the API refuses it.
  • Admin pages under /_cwa need no extra configuration.
主要言語
Vue
スター
0
フォーク
0
PR マージ指標
30日以内にマージされた PR はありません

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

components-web-app/docs のほかの issue

components-web-app/docs の issue をすべて見る

似ている issue

Documentation の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。