From b19800e97d62e59651d55dadbf1f38054cff071c Mon Sep 17 00:00:00 2001 From: mo Date: Tue, 21 Jul 2026 21:44:16 +0200 Subject: [PATCH] fix: /app publiek toegankelijk (SPA regelt zelf auth) --- server.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/server.js b/server.js index 48c0be4..62cf8ba 100644 --- a/server.js +++ b/server.js @@ -48,7 +48,7 @@ app.use((req, res, next) => { app.use((req, res, next) => { const publicPaths = ['/login', '/auth/login', '/css/dynamic.css', '/js/theme.js', '/health', '/api/spa/auth/login']; - const publicPrefixes = ['/wachtwoord-vergeten', '/wachtwoord-reset/', '/css/', '/js/', '/health']; + const publicPrefixes = ['/wachtwoord-vergeten', '/wachtwoord-reset/', '/css/', '/js/', '/health', '/app']; if (!publicPaths.includes(req.path) && !publicPrefixes.some(p => req.path.startsWith(p)) && !req.session.userId) { // API-aanroepen krijgen 401 JSON i.p.v. een HTML-redirect (o.a. voor de React SPA) if (req.path.startsWith('/api/')) {