feat(quick-260917-gyd): Ruecksprung nach Anmeldung auf urspruenglich angeforderte Seite
- safe-next.ts: buildNextParam()/sanitizeNextPath() als reine, getestete Funktionen (Open-Redirect-Schutz) - middleware.ts: haengt next-Parameter an beide Login-Umleitungen (fehlendes Cookie, ungueltige Signatur) - login/page.tsx: springt nach erfolgreicher Anmeldung auf den bereinigten next-Wert Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -5,6 +5,7 @@ import { useTranslations } from 'next-intl';
|
||||
import { useRouter } from 'next/navigation';
|
||||
import Link from 'next/link';
|
||||
import { login } from '@/lib/auth-actions';
|
||||
import { sanitizeNextPath } from '@/lib/safe-next';
|
||||
import { BRAND_YELLOW } from '@/components/brand/brand';
|
||||
import { TesseraLogo } from '@/components/brand/tessera-logo';
|
||||
import { DesktopDownloadLinks } from '@/components/desktop/desktop-download-links';
|
||||
@@ -30,7 +31,12 @@ export default function LoginPage() {
|
||||
startTransition(async () => {
|
||||
const result = await login(formData);
|
||||
if (result.success) {
|
||||
window.location.href = '/';
|
||||
// `next` erst beim Absenden aus window.location.search lesen statt
|
||||
// per useSearchParams(): der Hook verlangt in Next 15 eine
|
||||
// Suspense-Grenze, sonst bricht `next build` fuer die statisch
|
||||
// vorgerenderte Anmeldeseite ab (quick-260917-gyd).
|
||||
const next = new URLSearchParams(window.location.search).get('next');
|
||||
window.location.href = sanitizeNextPath(next);
|
||||
} else {
|
||||
setError(result.error ?? 'invalidCredentials');
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user