Skip to content

Require authentication on API routes; upgrade Next.js - #69

Merged
Wassim Chegham (manekinekko) merged 1 commit into
mainfrom
require-api-auth
Sep 29, 2026
Merged

Wassim Chegham (manekinekko) merged 1 commit into
mainfrom
require-api-auth

Conversation

@manekinekko

Copy link
Copy Markdown
Contributor

What changed

  • Every /api/* route now checks the caller first, in a root middleware.ts and again in each route handler. AUTH_MODE controls the check:
    • unset: anonymous access under npm run dev, 401 under npm start and in the container image
    • easyauth: requires the Azure Container Apps built-in authentication principal header
    • anonymous: explicit opt-out
  • Upgrade next and eslint-config-next to 15.5.25.
  • Add .dockerignore so .env* and .azure stay out of the image.
  • README: how to turn on sign-in for a deployment.

Heads-up for deployers

After this change, a new deployment's API returns 401 until built-in authentication is turned on and AUTH_MODE=easyauth is set (see README, Security). A follow-up will configure this automatically in Bicep.

Testing

  • npm ci with the updated lockfile and tsc --noEmit pass.
  • Verified locally: anonymous API requests get 401, signed-in requests work, and uploads up to 40 MB go through.

API routes now check the caller before doing any work. AUTH_MODE
controls the check: "easyauth" trusts the Azure Container Apps
built-in authentication headers, "anonymous" opts out, and when it
is unset only development builds allow anonymous access.

Also upgrade next and eslint-config-next to 15.5.25, add a
.dockerignore so local env files stay out of the image, and document
how to turn on sign-in.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant