fix(web): exclude large-upload route from auth middleware (10MB body cap)

The real cause of the failed 584MB album upload: Next.js caps the request body
at 10MB for any route that passes through middleware, and the import route went
through the auth gate. Exclude /api/library/import from the middleware matcher so
the body streams uncapped to busboy, and authenticate it inline instead (new
lib/auth.isAuthed reads + verifies the session cookie from the request).

web 161 tests, tsc + build clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jonathan
2026-07-14 14:41:06 +02:00
parent ce628ca245
commit 36a34181c9
3 changed files with 21 additions and 2 deletions
+7
View File
@@ -6,6 +6,7 @@ import { pipeline } from "node:stream/promises";
import { randomUUID } from "node:crypto";
import Busboy from "busboy";
import { prisma } from "@/lib/db";
import { isAuthed } from "@/lib/auth";
// Manually import an album (a ripped CD / files already on the PC): upload the audio (+ an
// optional cover) with artist/album/year, and Lyra writes it into the library. The web
@@ -25,6 +26,12 @@ function safeName(s: string): string {
}
export async function POST(request: Request) {
// This route is excluded from the auth middleware (to avoid the 10MB body cap), so it must
// authenticate itself.
if (!(await isAuthed(request))) {
return Response.json({ error: "unauthorized" }, { status: 401 });
}
const ct = request.headers.get("content-type") ?? "";
if (!ct.includes("multipart/form-data") || !request.body) {
return Response.json({ error: "expected multipart form data" }, { status: 400 });