feat(web): make /welcome a public path

The landing page must render without a session. Add /welcome to
isPublicPath so the auth middleware lets it through (alongside /healthz
and /auth/*), and assert the bypass in the public-paths test.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-03 21:48:25 +02:00
co-authored by Claude Opus 4.8
parent 6b817f11b9
commit d83943c86a
2 changed files with 2 additions and 2 deletions
+1 -1
View File
@@ -305,5 +305,5 @@ func (d *DexAuth) clearSessionCookie(w http.ResponseWriter) {
}
func isPublicPath(p string) bool {
return p == "/healthz" || strings.HasPrefix(p, "/auth/")
return p == "/healthz" || p == "/welcome" || strings.HasPrefix(p, "/auth/")
}