import { auth } from "@/lib/auth" export default auth((req) => { // Allow access to public pages if (req.nextUrl.pathname === "/" || req.nextUrl.pathname.startsWith("/auth/") || req.nextUrl.pathname.startsWith("/api/auth/") || req.nextUrl.pathname.startsWith("/api/privacy-policies")) { return } // Check if user is authenticated for admin routes if (req.nextUrl.pathname.startsWith("/admin") || req.nextUrl.pathname.startsWith("/api/users")) { if (!req.auth) { const url = new URL("/auth/signin", req.nextUrl.origin) return Response.redirect(url) } // Check if user has admin access const userRole = req.auth.user?.role if (userRole !== "ADMIN" && userRole !== "SUPER_ADMIN") { const url = new URL("/auth/signin", req.nextUrl.origin) return Response.redirect(url) } } }) export const config = { matcher: [ /* * Match all request paths except for the ones starting with: * - _next/static (static files) * - _next/image (image optimization files) * - favicon.ico (favicon file) * Also match all API routes */ "/((?!_next/static|_next/image|favicon.ico).*)", ], }