From 718d6e76e19c9eebfc0e9162fee762347f351849 Mon Sep 17 00:00:00 2001 From: Padreug Date: Tue, 15 Sep 2026 23:10:26 +0200 Subject: [PATCH] feat(auth): send the user back to ?redirect= after login Both login pages always landed on '/'. A page that needs an identity (chatelet's Book button) can now bounce an anonymous user through /login?redirect= and get them back. Only same-origin absolute paths are honoured; anything else falls back to home. Co-Authored-By: Claude Fable 5.1 --- src/lib/router-helpers.ts | 13 +++++++++++++ src/pages/Login.vue | 8 +++++--- src/pages/LoginDemo.vue | 12 +++++++----- 3 files changed, 25 insertions(+), 8 deletions(-) diff --git a/src/lib/router-helpers.ts b/src/lib/router-helpers.ts index f80f4ab..84bec63 100644 --- a/src/lib/router-helpers.ts +++ b/src/lib/router-helpers.ts @@ -77,3 +77,16 @@ export const catchAllRoute: RouteRecordRaw = { path: '/:pathMatch(.*)*', redirect: '/', } + +/** + * Where to send the user after a successful login. Honours a `?redirect=` + * query param so a page can bounce an anonymous user through /login and + * back (e.g. chatelet's Book button). Only same-origin absolute paths are + * accepted — anything else (external URLs, protocol-relative `//host`) + * falls back to home. + */ +export function postLoginTarget(redirect: unknown): string { + if (typeof redirect !== 'string') return '/' + if (!redirect.startsWith('/') || redirect.startsWith('//')) return '/' + return redirect +} diff --git a/src/pages/Login.vue b/src/pages/Login.vue index ff89413..7a440c7 100644 --- a/src/pages/Login.vue +++ b/src/pages/Login.vue @@ -111,7 +111,8 @@