fix: AdminAuth prefix matched too greedily
All checks were successful
Build and Deploy to Production / build (push) Successful in 46s
Build and Deploy to Production / deploy (push) Successful in 25s

start_with?('/admin') also matched /admin-invoice-form.js, returning 401
for the public JS asset that the New Invoice form depends on. Without it,
the "+ add line" button did nothing.

Require either the bare /admin path or a /admin/-prefixed one so sibling
assets in public/ that happen to share the prefix stay reachable.
This commit is contained in:
Sergei Poljanski 2026-05-26 18:31:32 +03:00
commit c7fe108ecf
Signed by: asxpi
GPG key ID: 4F8851660FA4121B

View file

@ -10,7 +10,8 @@ class AdminAuth
end
def call(env)
return @app.call(env) unless env['PATH_INFO'].to_s.start_with?('/admin')
path = env['PATH_INFO'].to_s
return @app.call(env) unless path == '/admin' || path.start_with?('/admin/')
auth = Rack::Auth::Basic::Request.new(env)
if @user && @pass && auth.provided? && auth.basic? && auth.credentials == [@user, @pass]