import { NextResponse } from 'next/server' import type { NextRequest } from 'next/server' import { updateSession } from '@/lib/auth' export async function middleware(request: NextRequest) { const session = request.cookies.get('session')?.value const isAuthPage = request.nextUrl.pathname.startsWith('/login') if (!session && !isAuthPage) { return NextResponse.redirect(new URL('/login', request.url)) } if (session && isAuthPage) { return NextResponse.redirect(new URL('/', request.url)) } // Handle rolling session let res = NextResponse.next() if (session && !isAuthPage) { const newSessionToken = await updateSession(request) if (newSessionToken) { res.cookies.set('session', newSessionToken, { httpOnly: true, secure: false, sameSite: 'lax', path: '/', maxAge: 2 * 60 * 60 // 2 hours }) } } return res } export const config = { matcher: [ /* * Match all request paths except for the ones starting with: * - api (API routes) * - _next/static (static files) * - _next/image (image optimization files) * - favicon.ico (favicon file) */ '/((?!api|_next/static|_next/image|favicon.ico).*)', ], }