import { Navigate, Outlet, useLocation } from 'react-router-dom'; import { useAuth } from '@/lib/AuthContext'; /** * Gate on the Admin console. * * It asks the auth context, which reflects `GET /me` — a real question to the * server about a real session — rather than the `sessionStorage` flag it used * to read. That flag could be set from the browser console; a session row keyed * by an HttpOnly cookie cannot. * * This guard is deliberately kept even though it now sits inside * `ProtectedRoute`, which checks the same thing. It is not redundant defence in * depth for its own sake: it is the component that owns "the Admin console is * entered through its own sign-in", and it is where a role check will go in * Phase 3D, when being signed in stops being sufficient to be here. * * The attempted path travels along in location state, so signing in returns you * to where you were going rather than dropping you on the Control Center. That * matters for a bookmarked deep link — an operator who saved /admin/activity * should land on Activity, not have to navigate there again. */ export default function AdminRoute() { const location = useLocation(); const { isAuthenticated, isLoadingAuth, authChecked } = useAuth(); // ProtectedRoute has already waited for the check, so this is belt and // braces: without it a direct render of this route would redirect to the // login page during the first tick and bounce a signed-in operator out. if (isLoadingAuth || !authChecked) return null; if (!isAuthenticated) { return ; } return ; }