DC-044: fix legacy /api/auth/totp/check-session shim path (drop /auth)
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled

The shim added in the previous commit rewrote /api/auth/totp/check-session
to /api/v1/auth/totp/check-session, but the canonical route is mounted at
/totp/check-session (no /auth prefix). The 404 returned to the auto-login
JS path was Route GET /v1/auth/totp/check-session — Express's /api/v1
mount stripped the /api/v1 prefix, leaving /auth/totp/check-session, which
doesn't match /totp/check-session.

Drop both /api and /auth (9 chars) so the legacy path maps to the
canonical /api/v1/totp/check-session.

Verified after deploy:
  GET /api/auth/totp/check-session  -> {"authenticated":true}
  GET /api/v1/totp/check-session    -> {"authenticated":true}
This commit is contained in:
Krystie
2026-07-08 21:33:07 -07:00
parent a7b0714643
commit cf8909740f
+15 -7
View File
@@ -196,15 +196,23 @@ async function createApp() {
// three auth paths to the v1 mount so the gate is tolerant of that drift. // three auth paths to the v1 mount so the gate is tolerant of that drift.
// Must run before configureMiddleware() so CSRF/auth see the canonical path. // Must run before configureMiddleware() so CSRF/auth see the canonical path.
// This is deliberately narrow — NOT a general `/api` -> `/api/v1` alias. // This is deliberately narrow — NOT a general `/api` -> `/api/v1` alias.
// /api/auth/totp/check-session is added because the auto-login page JS in //
// sso-gate.js (buildLoginPage) uses the legacy prefix; without this rewrite // Path mapping (legacy -> canonical):
// the JS gets a 404 and the page hangs at "Signing in to Plex..." forever // /api/auth/gate/<id> -> /api/v1/auth/gate/<id> (mounted at /auth/gate/:serviceId)
// (user-reported 2026-07-09). // /api/auth/app-token/<id> -> /api/v1/auth/app-token/<id> (mounted at /auth/app-token/:serviceId)
// /api/auth/totp/check-session -> /api/v1/totp/check-session (mounted at /totp/check-session — no /auth prefix)
//
// The totp case drops `/auth` because the canonical route is /totp/check-session
// (no /auth prefix) but the legacy JS still uses /api/auth/totp/check-session.
// Without this rewrite the JS gets a 404 and the page hangs at
// "Signing in to Plex..." forever (user-reported 2026-07-09).
app.use((req, res, next) => { app.use((req, res, next) => {
if (req.url.startsWith('/api/auth/gate/') if (req.url.startsWith('/api/auth/gate/') || req.url.startsWith('/api/auth/app-token/')) {
|| req.url.startsWith('/api/auth/app-token/')
|| req.url.startsWith('/api/auth/totp/check-session')) {
req.url = '/api/v1' + req.url.slice(4); // '/api'.length === 4 req.url = '/api/v1' + req.url.slice(4); // '/api'.length === 4
} else if (req.url.startsWith('/api/auth/totp/check-session')) {
// Legacy: /api/auth/totp/check-session -> /api/v1/totp/check-session
// Drop both '/api' and '/auth' prefixes (9 chars total).
req.url = '/api/v1' + req.url.slice(9); // '/api/auth'.length === 9
} }
next(); next();
}); });