import { auth } from "@/auth"; import { NextResponse } from "next/server"; // Public routes that don't require authentication const publicRoutes = ["/login", "/signup", "/forgot-password", "/reset-password", "/verify-email", "/contact"]; export default auth((req) => { const { nextUrl } = req; const isLoggedIn = !!req.auth; const userRole = (req.auth?.user as any)?.role; const isPublicRoute = publicRoutes.some( (route) => nextUrl.pathname === route || nextUrl.pathname.startsWith(route + "/") ); const isAgentRoute = nextUrl.pathname.startsWith("/agent"); const isUserRoute = nextUrl.pathname.startsWith("/user"); const isApiRoute = nextUrl.pathname.startsWith("/api"); const isStaticRoute = nextUrl.pathname.startsWith("/_next") || nextUrl.pathname.startsWith("/assets") || nextUrl.pathname.includes("."); // Skip middleware for API routes and static files if (isApiRoute || isStaticRoute) { return NextResponse.next(); } // Redirect logged-in users away from public routes (login, signup) if (isLoggedIn && isPublicRoute) { // Redirect to home page instead of dashboard return NextResponse.redirect(new URL("/", nextUrl.origin)); } // Redirect non-logged-in users to login page for protected routes if (!isLoggedIn && !isPublicRoute) { const loginUrl = new URL("/login", nextUrl.origin); loginUrl.searchParams.set("callbackUrl", nextUrl.pathname); return NextResponse.redirect(loginUrl); } // Role-based route protection if (isLoggedIn) { // Prevent regular users from accessing agent routes if (isAgentRoute && userRole !== "AGENT") { return NextResponse.redirect(new URL("/user/userdashboard", nextUrl.origin)); } // Prevent agents from accessing user routes if (isUserRoute && userRole === "AGENT") { return NextResponse.redirect(new URL("/agent/dashboard", nextUrl.origin)); } } return NextResponse.next(); }); export const config = { matcher: ["/((?!_next/static|_next/image|favicon.ico).*)"], };