fix(09): WR-10 fail boot when another plugin already owns the backend guard

This commit is contained in:
Jakub Zych
2026-10-01 21:15:05 +02:00
parent 20a79c5df4
commit 3f476164f9
4 changed files with 50 additions and 6 deletions

View File

@@ -113,10 +113,12 @@ func Activate(app *backpack.App, plugins []party.Plugin) (*Routes, error) {
bl := adminBlacklist(app)
users := lazyBackendUsers{app: app, reg: reg}
guard := bouncer.NewBackendJWTGuard(secret, users, bl, writeUnauthenticated, AdminCookieName)
if _, err := guards.Middleware("backend"); err != nil {
if err := guards.Register("summercms.cabana", "backend", guard); err != nil {
return nil, err
}
// The admin API is only as strong as this guard (audience, secret, user
// provider), so cabana always registers its own and never mounts the API
// behind a guard another plugin already put under the name "backend": a
// taken name fails boot instead of silently replacing admin authentication.
if err := guards.Register("summercms.cabana", "backend", guard); err != nil {
return nil, fmt.Errorf("cabana: backend guard: %w", err)
}
mw, err := guards.Middleware("backend")
if err != nil {