Recommend router-based route protection over pathname-string auth checks - #14432
Merged
Conversation
Contributor
Lunaria Status Overview🌕 This pull request will trigger status changes. Learn moreBy default, every PR changing files present in the Lunaria configuration's You can change this by adding one of the keywords present in the Tracked Files
Warnings reference
|
|
Preview deployment ✅ Deployment complete!
|
matthewp
marked this pull request as ready for review
August 19, 2026 18:17
ArmandPhilippot
approved these changes
Aug 19, 2026
ArmandPhilippot
left a comment
Member
There was a problem hiding this comment.
I left two suggestions regarding the caution, which may be a bit long for a single paragraph (especially the first one).
Otherwise, LGTM! And, you plan for v8 makes sense to me! 👍🏽
Co-authored-by: Armand Philippot <git@armand.philippot.eu>
Co-authored-by: Armand Philippot <git@armand.philippot.eu>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description (required)
In the path we have documenting using patterns like
context.url.pathname.startsWith('/dashboard')to only apply auth requirements to certain routes. This had led to numerous security issues such as double-encoded URLs, base-stripped URLs not matching the string check, etc. It was a mistake for Astro to make Astro.url by anything other than the raw request URL. We have attempted to "normalize" this value for users to match what they expect. If the user is going to thedashboard.astroroute they expect the URL to also be/dashboard. But this means that Astro has taken on the burden of the pathname not actually matching user expectations.I hope to make a breaking change to how Astro.url works in 8.0 so that we no longer normalize the value for the user at all. In the mean time I want to immediately move away from documenting a bad practice. Instead if you want to apply middleware to certain routes, use a router like Hono.
This updates the docs both to show the preferred method, as well as to discourage the old.
References
Not related to any pull-requests or Astro issues.