X Enterprises
fastify-xauth-nile

Protect path surfaces

Guard /admin, /portal, and /affiliates with protectedPaths — the Fastify analogue of xAuthBetter prefix and JWKS pathPattern.

Protect path surfaces

protectedPaths is plugin-owned. It is the place for your app routes (/admin, /portal), not Nile's generated auth URLs.

SDK routes (SIGNIN, CSRF, ME, …) only remaps nile-auth endpoints. Putting ME: "/admin" would steal identity onto the admin app.

Configure the three surfaces

protectedPaths: [
  { prefix: "/admin", access: "platform" },
  { prefix: "/portal", access: "session" },
  { prefix: "/affiliates", access: "tenant" },
],
excludedPaths: ["/portal/health"],
superAdmins: ["ops@example.com"],
accessPrefixChecks
platform/adminSession + superAdmins allowlist (id or email). No tenant required
session/portalSession only
tenant/affiliatesSession + tenant id (URL param / header / cookie)

prefix is a directory guard: /admin and /admin/stats match. Matching is boundary-aware — /admin does not match /administrator or /admin-extra (unlike xAuthBetter startsWith).

Add the platform entry only when superAdmins is a non-empty array. Registration throws if access: "platform" is set with an empty allowlist.

Skip public children

excludedPaths: ["/portal/health"]

Per-entry excludedPaths override the instance list. Mounted Nile routes (/api/auth/*, /api/me, …) are always skipped so CSRF stays public.

Guard a single route

Routes outside these prefixes use preHandlers:

const auth = fastify.xAuthNile.default;

fastify.get("/internal/stats", {
  preHandler: [auth.requireAuth(), auth.requireSuperAdmin()],
}, async (request) => ({ user: request.user }));

Legacy prefix: "/api" is session-only shorthand for a single surface. Prefer protectedPaths when you have /admin and /portal.

When guarding surfaces outside routePrefix (e.g. /portal or /admin when routePrefix is /api), configure cookiePath: "/" in instance options so browsers send Nile session cookies to both /api and out-of-prefix routes without requiring proxy-level cookie rewrites.

See also

AI Context

package: "@xenterprises/fastify-xauth-nile"
method: configs[].protectedPaths
use-when: guard Fastify app prefixes — /admin platform, /portal session, /affiliates tenant; not for remapping /api/auth/csrf
usage: protectedPaths: [{ prefix: '/admin', access: 'platform' }, { prefix: '/portal', access: 'session' }]
Copyright © 2026