Signing in from a deep link lands on the home page #47

Open
opened 2026-10-03 19:44:39 +00:00 by jalenluorion · 0 comments
Member

What's wrong
If you open a link such as /explore while signed out, you see the welcome page. After signing in you land on /, not on the page you opened.

How to reproduce

  1. Sign out, then open /explore (or /manager).
  2. Click "Sign in with CMU" and finish signing in.
  3. You land on / instead of /explore.

Expected
After sign-in you return to the page you opened, query string included (except login_error).

Where to look

  • web/src/app/components/Welcome.tsx: the link uses signInUrl("/"). Build the return path from usePathname() and useSearchParams() (already imported there), dropping login_error.
  • web/src/context/AuthContext.tsx: signInUrl.
  • web/src/server/auth/session.ts: safeReturnTo already rejects off-site paths, so a local path is safe to pass.

Done when

  • Signing in from /explore returns to /explore; from / it still returns to /.
  • A failed sign-in does not carry login_error into the next attempt.
  • A small test covers the return path the link builds.
**What's wrong** If you open a link such as /explore while signed out, you see the welcome page. After signing in you land on `/`, not on the page you opened. **How to reproduce** 1. Sign out, then open /explore (or /manager). 2. Click "Sign in with CMU" and finish signing in. 3. You land on `/` instead of /explore. **Expected** After sign-in you return to the page you opened, query string included (except `login_error`). **Where to look** - `web/src/app/components/Welcome.tsx`: the link uses `signInUrl("/")`. Build the return path from `usePathname()` and `useSearchParams()` (already imported there), dropping `login_error`. - `web/src/context/AuthContext.tsx`: `signInUrl`. - `web/src/server/auth/session.ts`: `safeReturnTo` already rejects off-site paths, so a local path is safe to pass. **Done when** - [ ] Signing in from /explore returns to /explore; from `/` it still returns to `/`. - [ ] A failed sign-in does not carry `login_error` into the next attempt. - [ ] A small test covers the return path the link builds.
jalenluorion added this to the Phase 1 milestone 2026-10-03 19:44:39 +00:00
jalenluorion added this to the CMUCal project 2026-10-03 19:45:09 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ScottyLabs/cal#47
No description provided.