import type { MiddlewareHandler } from "hono"; import type { AppBindings } from "@/worker/hono"; // Better Auth's `admin` plugin exposes a wide surface (create-user, // set-user-password, impersonate-user, remove-user, session revocation, ...) // that tessera does not use. tessera registration is invite-only, so a // signed-in admin should not be able to bypass invites by hitting the raw // /api/auth/admin/create-user endpoint just because it remains mounted. // // Allowlist the routes the tessera admin UI actually drives, keyed on // (path, method). Everything else under /api/auth/admin/* returns 404 // before reaching Better Auth, including wrong-method calls on listed // paths (POST /admin/list-users, GET /admin/set-role). // // `/api/auth/admin/ban-user` is intentionally excluded here because it // is served by the tessera handler in `api/admin/users.ts` (mounted // before this middleware runs in `worker/index.ts`); the cleanup needs // to happen atomically with the ban flag flip. type Method = "GET" | "POST"; const ADMIN_ALLOWLIST: ReadonlyMap = new Map([ ["/api/auth/admin/list-users", "GET"], ["/api/auth/admin/set-role", "POST"], ["/api/auth/admin/unban-user", "POST"], ]); export const adminRouteAllowlist: MiddlewareHandler = async (c, next) => { const allowedMethod = ADMIN_ALLOWLIST.get(c.req.path); if (allowedMethod && c.req.method === allowedMethod) { await next(); return; } return new Response("Not Found", { status: 404 }); };