feat(quick-260917-gyd): Ruecksprung nach Anmeldung auf urspruenglich angeforderte Seite

- safe-next.ts: buildNextParam()/sanitizeNextPath() als reine, getestete Funktionen (Open-Redirect-Schutz)
- middleware.ts: haengt next-Parameter an beide Login-Umleitungen (fehlendes Cookie, ungueltige Signatur)
- login/page.tsx: springt nach erfolgreicher Anmeldung auf den bereinigten next-Wert

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-09-17 12:26:14 +02:00
parent 4778824c73
commit 4b279eac70
4 changed files with 98 additions and 3 deletions
+7 -1
View File
@@ -5,6 +5,7 @@ import { useTranslations } from 'next-intl';
import { useRouter } from 'next/navigation';
import Link from 'next/link';
import { login } from '@/lib/auth-actions';
import { sanitizeNextPath } from '@/lib/safe-next';
import { BRAND_YELLOW } from '@/components/brand/brand';
import { TesseraLogo } from '@/components/brand/tessera-logo';
import { DesktopDownloadLinks } from '@/components/desktop/desktop-download-links';
@@ -30,7 +31,12 @@ export default function LoginPage() {
startTransition(async () => {
const result = await login(formData);
if (result.success) {
window.location.href = '/';
// `next` erst beim Absenden aus window.location.search lesen statt
// per useSearchParams(): der Hook verlangt in Next 15 eine
// Suspense-Grenze, sonst bricht `next build` fuer die statisch
// vorgerenderte Anmeldeseite ab (quick-260917-gyd).
const next = new URLSearchParams(window.location.search).get('next');
window.location.href = sanitizeNextPath(next);
} else {
setError(result.error ?? 'invalidCredentials');
}