internal/middleware/middleware.go:394-430 and internal/server/routes.go:29
Description
SetupRequired is applied as global middleware on ALL routes (s.router.Use(s.mw.SetupRequired())). When no user exists (fresh install), it redirects everything except /setup to /setup.
This breaks:
/health — returns 303 redirect instead of 200 JSON. Load balancers and monitoring systems will consider the service down during the setup window.
/s/* (static assets) — CSS/JS for the setup page itself cannot load, so the setup page renders unstyled.
/api/v1/* — API routes get HTML redirects instead of JSON errors.
/webhook/* — webhooks return redirects.
Impact
Load balancers may refuse to route traffic to a freshly deployed instance, preventing initial setup
The setup page itself has broken styling (no CSS/JS)
## Severity: HIGH
## File & Line
`internal/middleware/middleware.go:394-430` and `internal/server/routes.go:29`
## Description
`SetupRequired` is applied as global middleware on ALL routes (`s.router.Use(s.mw.SetupRequired())`). When no user exists (fresh install), it redirects everything except `/setup` to `/setup`.
This breaks:
1. **`/health`** — returns 303 redirect instead of 200 JSON. Load balancers and monitoring systems will consider the service down during the setup window.
2. **`/s/*` (static assets)** — CSS/JS for the setup page itself cannot load, so the setup page renders unstyled.
3. **`/api/v1/*`** — API routes get HTML redirects instead of JSON errors.
4. **`/webhook/*`** — webhooks return redirects.
## Impact
- Load balancers may refuse to route traffic to a freshly deployed instance, preventing initial setup
- The setup page itself has broken styling (no CSS/JS)
- API clients get unexpected redirect responses
## Suggested Fix
Exempt paths that should work without setup:
```go
if setupRequired {
path := request.URL.Path
if path == "/setup" || path == "/health" || strings.HasPrefix(path, "/s/") {
next.ServeHTTP(writer, request)
return
}
http.Redirect(writer, request, "/setup", http.StatusSeeOther)
return
}
```
clawbot
added this to the 1.0 milestone 2026-02-20 12:28:56 +01:00
clawbot
added the bug label 2026-02-20 12:28:56 +01:00
clawbot
self-assigned this 2026-02-20 12:28:56 +01:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Severity: HIGH
File & Line
internal/middleware/middleware.go:394-430andinternal/server/routes.go:29Description
SetupRequiredis applied as global middleware on ALL routes (s.router.Use(s.mw.SetupRequired())). When no user exists (fresh install), it redirects everything except/setupto/setup.This breaks:
/health— returns 303 redirect instead of 200 JSON. Load balancers and monitoring systems will consider the service down during the setup window./s/*(static assets) — CSS/JS for the setup page itself cannot load, so the setup page renders unstyled./api/v1/*— API routes get HTML redirects instead of JSON errors./webhook/*— webhooks return redirects.Impact
Suggested Fix
Exempt paths that should work without setup: