fix: serve static assets correctly under /session/* routes
When the browser loads a session page at /session/<id>, it requests static assets relative to that path — e.g. /session/static/style.css. The /session/* catch-all in handle_get() intercepted those requests and returned the HTML index page (text/html), causing browsers to refuse the stylesheet with a MIME-type mismatch error. Two-part fix: - routes.py: add a guard before the /session/ catch-all that strips the /session prefix from /session/static/* paths and delegates to _serve_static(), so the correct Content-Type is returned. - auth.py: whitelist /session/static/* in check_auth() alongside /static/, so static assets on session pages are served without requiring an authenticated session (same policy as /static/). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -217,7 +217,7 @@ def check_auth(handler, parsed) -> bool:
|
||||
if not is_auth_enabled():
|
||||
return True
|
||||
# Public paths don't require auth
|
||||
if parsed.path in PUBLIC_PATHS or parsed.path.startswith('/static/'):
|
||||
if parsed.path in PUBLIC_PATHS or parsed.path.startswith('/static/') or parsed.path.startswith('/session/static/'):
|
||||
return True
|
||||
# Check session cookie
|
||||
cookie_val = parse_cookie(handler)
|
||||
|
||||
Reference in New Issue
Block a user