Skip to content

[6.x] Isolate CP authentication from site middleware - #19941

Open
riasvdv wants to merge 2 commits into
6.xfrom
fix/cp-craft-web-routes
Open

riasvdv wants to merge 2 commits into
6.xfrom
fix/cp-craft-web-routes

Conversation

@riasvdv

@riasvdv riasvdv commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Description

Site middleware appended to craft.web, such as a project’s Inertia middleware, currently runs on control panel authentication routes and can overwrite Craft’s Inertia configuration.

Apply RunQueue directly to those routes instead, and add AuthenticateCraftSession to craft.cp so session validation covers all control panel routes. Skip session validation for token guards.

@github-actions

Copy link
Copy Markdown

📚 Storybook previews

@craftcms/ui — open Storybook

No changed components detected in this Storybook.

resources/js — open Storybook

No changed components detected in this Storybook.

@riasvdv
riasvdv requested a review from brandonkelly October 10, 2026 21:22
@github-actions

Copy link
Copy Markdown

This PR had conflicts with 6.x. Claude attempted an automatic resolution and pushed a merge commit. Please review the merge commit carefully before approving/merging.

Claude's response

I resolved the merge and committed it as 8379e07. I haven't pushed it.

The only file with a conflict was CHANGELOG.md, in the unreleased changes section. Both sides had added new "Fixed" entries at the same spot. This branch added two: one about site Inertia middleware in craft.web breaking control panel authentication pages, and one about stale password hashes not invalidating sessions. 6.x added two entries about asset folders in asset selection modals (#19937). I kept all four, with this branch's entries first and the 6.x entries after them.

None of it was ambiguous, so I didn't add any # CONFLICT-REVIEW: comments.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant