From d83943c86a41fb63ab77ac90f6ea7072fa7fd195 Mon Sep 17 00:00:00 2001 From: Mathias Date: Wed, 3 Jun 2026 21:48:25 +0200 Subject: [PATCH] feat(web): make /welcome a public path The landing page must render without a session. Add /welcome to isPublicPath so the auth middleware lets it through (alongside /healthz and /auth/*), and assert the bypass in the public-paths test. Co-Authored-By: Claude Opus 4.8 (1M context) --- internal/web/oidc/oidc.go | 2 +- internal/web/oidc/oidc_test.go | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/internal/web/oidc/oidc.go b/internal/web/oidc/oidc.go index 57da714..d42a5c1 100644 --- a/internal/web/oidc/oidc.go +++ b/internal/web/oidc/oidc.go @@ -305,5 +305,5 @@ func (d *DexAuth) clearSessionCookie(w http.ResponseWriter) { } func isPublicPath(p string) bool { - return p == "/healthz" || strings.HasPrefix(p, "/auth/") + return p == "/healthz" || p == "/welcome" || strings.HasPrefix(p, "/auth/") } diff --git a/internal/web/oidc/oidc_test.go b/internal/web/oidc/oidc_test.go index 929cdff..889aa80 100644 --- a/internal/web/oidc/oidc_test.go +++ b/internal/web/oidc/oidc_test.go @@ -280,7 +280,7 @@ func TestMiddlewarePublicPathsBypassAuth(t *testing.T) { w.WriteHeader(http.StatusOK) })) - for _, path := range []string{"/healthz", "/auth/login"} { + for _, path := range []string{"/healthz", "/welcome", "/auth/login"} { rec := httptest.NewRecorder() guarded.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, path, nil)) require.Equal(t, http.StatusOK, rec.Code, "expected %s to bypass auth", path)