Send signed-out visitors back where they were after login - #426
Merged
Merged
Conversation
aamoghS
added this pull request to stack #436
September 25, 2026 13:34
Contributor
Author
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
aamoghS
approved these changes
Sep 25, 2026
Every portal page redirected signed-out visitors to a bare /login, and the login page falls back to /dashboard. A shared hackathon, judging, registration or submit link lost its destination the moment it asked somebody to sign in: a stranger pressing "Register now" on /hacklytics signed in and landed on the dashboard. loginHref() (lib/safe-callback.ts) builds /login?callbackUrl=<current path>; the login page already validates it with safeCallback. All 17 redirects use it. /initiatives, /lead and /club/bootcamp had no signed-out redirect at all: their queries wait on the session, so a disabled query stayed pending and an expired session sat on the loading screen forever. They now redirect the same way.
aamoghS
force-pushed
the
fix/login-return-path
branch
from
September 25, 2026 13:35
cbe94b3 to
5838822
Compare
Contributor
Author
|
Visit the preview URL for this PR (updated for commit 15fde47): https://hacklytics2027--pr-426-enjcfvg5.web.app (expires Fri, 02 Oct 2026 14:13:05 GMT) 🔥 via Firebase Hosting GitHub Action 🌎 Sign: c48ba34db61581e25fe2978355160b5eefe0e83f |
# Conflicts: # sites/mainweb/app/(portal)/judge/register/page.tsx
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated PR tracking changes from
fix/login-return-pathintodev.Note
Low Risk
Broad but repetitive client-side redirect changes; post-login destinations still rely on existing
safeCallbackvalidation on the login flow.Overview
Signed-out users are sent to login with a return URL instead of a bare
/login, so after auth they land back on the deep link they opened (judge registration, hackathon pages, admin tools, etc.) rather than defaulting to/dashboard.Adds
loginHref()insafe-callback.ts, which encodes the currentpathname+searchascallbackUrl, and wires it through portal/admin layouts and pages that previously usedrouter.push("/login")orwindow.location.href = "/login".Bootcamp, initiatives, and lead now redirect unauthenticated visitors in a
useEffect(queries were gated on session, which left signed-out users stuck on loading forever).Reviewed by Cursor Bugbot for commit 15fde47. Bugbot is set up for automated code reviews on this repo. Configure here.