@@ -29,11 +29,14 @@ const PUBLIC_ROUTE_PREFIXES = ["/profiles/", "/nda-signing/"] as const;
2929
3030const AUTH_ROUTES = [ "/auth/sign-in" , "/auth/sign-up" , "/auth/onboarding" ] as const ;
3131
32- // Authentication status routes
32+ // Authentication status routes - these require auth but have special handling
3333const EMAIL_VERIFICATION_ROUTE = "/auth/verify" ;
3434const WAITING_APPROVAL_ROUTE = "/auth/waiting" ;
3535const APPLICATION_DECLINED_ROUTE = "/auth/declined" ;
36- const APPLICANT_ROUTE = "/applicant"
36+ const APPLICANT_ROUTE = "/applicant" ;
37+
38+ // Routes that authenticated users can always access regardless of application status
39+ const AUTH_STATUS_ROUTES = [ APPLICATION_DECLINED_ROUTE , EMAIL_VERIFICATION_ROUTE ] as const ;
3740
3841const routePermissionMap : Record < string , keyof RolePermissions > = {
3942 "/home/interns" : "interns" ,
@@ -89,16 +92,14 @@ export async function middleware(req: NextRequest) {
8992 const supabase = await createClientServerComponent ( ) ;
9093 const {
9194 data : { user } ,
92- error,
9395 } = await supabase . auth . getUser ( ) ;
9496
95- // If error is related to missing refresh token, ignore it for auth routes
97+ // If user is already logged in, redirect to home
9698 if ( user ) {
97- // Redirect to home if user is already logged in
9899 return redirectTo ( req , "/home" ) ;
99100 }
100101
101- // Allow access to auth pages if not logged in, regardless of error
102+ // Allow access to auth pages if not logged in
102103 return NextResponse . next ( ) ;
103104 }
104105
@@ -120,10 +121,15 @@ export async function middleware(req: NextRequest) {
120121 return redirectToLogin ( req ) ;
121122 }
122123
124+ // Allow authenticated users to access auth status routes without further checks
125+ // This prevents redirect loops when users are being directed to these pages
126+ if ( AUTH_STATUS_ROUTES . includes ( pathname as any ) ) {
127+ return NextResponse . next ( ) ;
128+ }
129+
123130 // Check if email is verified
124131 const {
125132 data : { user : authUser } ,
126- error : verificationError ,
127133 } = await supabase . auth . getUser ( ) ;
128134
129135 if (
0 commit comments