Makes every client-side fetch('/api/...') call respect the mount prefix
when Bulwark is served behind a reverse proxy at a sub-path (e.g.
`/webmail`).
### Problem
`getPathPrefix()` (added in 1.4.13 by #XXX / d762b94) already fixes
router navigation and redirect URIs for reverse-proxy deployments.
Client-side `fetch()` calls, though, still target the browser origin:
await fetch('/api/foo')
// Browser at /webmail/en/inbox → hits /api/foo (not proxied → 404)
That means the login flow, session establishment, settings save, plugin
loader, calendar import, etc. all break the moment you front Bulwark
with nginx (or any proxy) at a sub-path.
### Fix
Add `apiFetch(input, init)` next to `getPathPrefix()` in
`lib/browser-navigation.ts`. It prepends the mount prefix to any
absolute path at call time:
await apiFetch('/api/foo')
// /webmail/en/inbox → /webmail/api/foo
// /en/inbox → /api/foo
Same runtime-detection model as `getPathPrefix()` — the built bundle
works at any mount point without rebuilding or env-var config.
Protocol-relative (`//cdn...`) and absolute (`https://...`) URLs pass
through unchanged. Server-side route handlers are untouched (the mount
prefix is a browser-only concept).
### Migration
Mechanical rewrite of every client-side `fetch('/api/...')` call in
hooks/, lib/, stores/, components/, app/ — 99 call sites across
26 files. `route.ts` handlers and other server-only files are skipped.
### Compat
- No behaviour change when mounted at `/` (the common case): an empty
prefix + raw path is identical to raw path.
- No new config knobs, env vars, or build flags.
- Supersedes PR #181 (which required a build-time `NEXT_PUBLIC_BASE_PATH`)
— will close #181 after this lands.
### Testing
Should run the existing suite; smoke-tested by Jabali Panel which
reverse-proxies Bulwark at `/webmail/` (https://github.com/shukiv/jabali-panel).
97 lines
2.9 KiB
TypeScript
97 lines
2.9 KiB
TypeScript
import { create } from 'zustand';
|
|
import type { SettingsPolicy, FeatureGates, SettingRestriction, ThemePolicy } from '@/lib/admin/types';
|
|
import { DEFAULT_POLICY, DEFAULT_THEME_POLICY } from '@/lib/admin/types';
|
|
import { apiFetch } from '@/lib/browser-navigation';
|
|
|
|
interface PolicyState {
|
|
policy: SettingsPolicy;
|
|
loaded: boolean;
|
|
fetchPolicy: () => Promise<void>;
|
|
isSettingLocked: (key: string) => boolean;
|
|
isSettingHidden: (key: string) => boolean;
|
|
isFeatureEnabled: (feature: keyof FeatureGates) => boolean;
|
|
getRestriction: (key: string) => SettingRestriction | undefined;
|
|
getEffectiveDefault: (key: string) => unknown;
|
|
getThemePolicy: () => ThemePolicy;
|
|
getForcedThemeId: (availableThemeIds?: string[]) => string | null;
|
|
isThemeDisabled: (themeId: string, isBuiltIn: boolean) => boolean;
|
|
isPluginForceEnabled: (pluginId: string) => boolean;
|
|
isPluginApproved: (pluginId: string) => boolean;
|
|
isThemeForceEnabled: (themeId: string) => boolean;
|
|
}
|
|
|
|
export const usePolicyStore = create<PolicyState>()((set, get) => ({
|
|
policy: { ...DEFAULT_POLICY },
|
|
loaded: false,
|
|
|
|
fetchPolicy: async () => {
|
|
try {
|
|
const res = await apiFetch('/api/admin/policy');
|
|
if (res.ok) {
|
|
const data = await res.json();
|
|
set({ policy: data, loaded: true });
|
|
} else {
|
|
set({ loaded: true });
|
|
}
|
|
} catch {
|
|
set({ loaded: true });
|
|
}
|
|
},
|
|
|
|
isSettingLocked: (key) => {
|
|
const r = get().policy.restrictions[key];
|
|
return r?.locked === true;
|
|
},
|
|
|
|
isSettingHidden: (key) => {
|
|
const r = get().policy.restrictions[key];
|
|
return r?.hidden === true;
|
|
},
|
|
|
|
isFeatureEnabled: (feature) => {
|
|
return get().policy.features[feature] ?? true;
|
|
},
|
|
|
|
getRestriction: (key) => {
|
|
return get().policy.restrictions[key];
|
|
},
|
|
|
|
getEffectiveDefault: (key) => {
|
|
return get().policy.defaults[key];
|
|
},
|
|
|
|
getThemePolicy: () => {
|
|
return get().policy.themePolicy || { ...DEFAULT_THEME_POLICY };
|
|
},
|
|
|
|
getForcedThemeId: (availableThemeIds) => {
|
|
const forceEnabledThemes = get().policy.forceEnabledThemes || [];
|
|
if (!availableThemeIds || availableThemeIds.length === 0) {
|
|
return forceEnabledThemes[0] || null;
|
|
}
|
|
|
|
const available = new Set(availableThemeIds);
|
|
return forceEnabledThemes.find((themeId) => available.has(themeId)) || null;
|
|
},
|
|
|
|
isThemeDisabled: (themeId, isBuiltIn) => {
|
|
const tp = get().policy.themePolicy || DEFAULT_THEME_POLICY;
|
|
if (isBuiltIn) {
|
|
return (tp.disabledBuiltinThemes || []).includes(themeId);
|
|
}
|
|
return (tp.disabledThemes || []).includes(themeId);
|
|
},
|
|
|
|
isPluginForceEnabled: (pluginId) => {
|
|
return (get().policy.forceEnabledPlugins || []).includes(pluginId);
|
|
},
|
|
|
|
isPluginApproved: (pluginId) => {
|
|
return (get().policy.approvedPlugins || []).includes(pluginId);
|
|
},
|
|
|
|
isThemeForceEnabled: (themeId) => {
|
|
return (get().policy.forceEnabledThemes || []).includes(themeId);
|
|
},
|
|
}));
|