Skip to content

Send signed-out visitors back where they were after login - #426

Merged
aamoghS merged 2 commits into
devfrom
fix/login-return-path
Sep 25, 2026
Merged

aamoghS merged 2 commits into
devfrom
fix/login-return-path

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Automated PR tracking changes from fix/login-return-path into dev.


Note

Low Risk
Broad but repetitive client-side redirect changes; post-login destinations still rely on existing safeCallback validation on the login flow.

Overview
Signed-out users are sent to login with a return URL instead of a bare /login, so after auth they land back on the deep link they opened (judge registration, hackathon pages, admin tools, etc.) rather than defaulting to /dashboard.

Adds loginHref() in safe-callback.ts, which encodes the current pathname + search as callbackUrl, and wires it through portal/admin layouts and pages that previously used router.push("/login") or window.location.href = "/login".

Bootcamp, initiatives, and lead now redirect unauthenticated visitors in a useEffect (queries were gated on session, which left signed-out users stuck on loading forever).

Reviewed by Cursor Bugbot for commit 15fde47. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions
github-actions Bot requested a review from aamoghS as a code owner September 25, 2026 03:01
@aamoghS aamoghS changed the title Feature: fix/login-return-path to dev Send signed-out visitors back where they were after login Sep 25, 2026
@aamoghS
aamoghS added this pull request to stack #436 September 25, 2026 13:34
@github-actions

Copy link
Copy Markdown
Contributor Author

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

Every portal page redirected signed-out visitors to a bare /login, and
the login page falls back to /dashboard. A shared hackathon, judging,
registration or submit link lost its destination the moment it asked
somebody to sign in: a stranger pressing "Register now" on /hacklytics
signed in and landed on the dashboard.

loginHref() (lib/safe-callback.ts) builds /login?callbackUrl=<current
path>; the login page already validates it with safeCallback. All 17
redirects use it.

/initiatives, /lead and /club/bootcamp had no signed-out redirect at
all: their queries wait on the session, so a disabled query stayed
pending and an expired session sat on the loading screen forever. They
now redirect the same way.
@aamoghS
aamoghS force-pushed the fix/login-return-path branch from cbe94b3 to 5838822 Compare September 25, 2026 13:35
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor Author

Visit the preview URL for this PR (updated for commit 15fde47):

https://hacklytics2027--pr-426-enjcfvg5.web.app

(expires Fri, 02 Oct 2026 14:13:05 GMT)

🔥 via Firebase Hosting GitHub Action 🌎

Sign: c48ba34db61581e25fe2978355160b5eefe0e83f

@github-actions github-actions Bot added the bug Something isn't working label Sep 25, 2026
# Conflicts:
#	sites/mainweb/app/(portal)/judge/register/page.tsx
@aamoghS aamoghS closed this Sep 25, 2026
@aamoghS aamoghS reopened this Sep 25, 2026
@aamoghS
aamoghS removed this pull request from stack #436 September 25, 2026 14:22
@aamoghS
aamoghS merged commit 5fe8bf9 into dev Sep 25, 2026
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

⤵️ pull bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant