import Cookies from 'js-cookie'; import { Navigate, Outlet, useLocation } from 'react-router-dom'; import type { ReactNode } from 'react'; import { authStorage } from '../utils/auth-storage'; interface ProtectedRouteProps { children?: ReactNode; loginPath?: string; } export function ProtectedRoute({ children, loginPath = '/login' }: ProtectedRouteProps) { const location = useLocation(); // `authStorage` is already scoped to this app; the bare key is only the // legacy pre-prefix session. Never read a sibling app's token — that is how // a backoffice tab ends up authenticated as a portal applicant. const token = authStorage.getToken() ?? Cookies.get('auth-token'); if (!token) { return ; } return children ? <>{children} : ; }