feat: add next parameter to login flow and redirect unauthenticated users to login page

- Add `next` field to LoginForm model for preserving post-login redirect target
- Implement `safe_next` utility to validate redirect URLs and prevent open redirect vulnerabilities
- Update login page handler to accept and pass `next` query parameter
- Add hidden `next` input to login form template for POST submission
- Modify `require_user` to redirect to `/auth/login` instead of root
- Add `Http.toLogin()` static method in JS for client-side redirect with current URL encoded
- Update CommentManager to redirect unauthenticated reply attempts to login
- Fix comment creation redirect to use `comment_url` instead of generic `redirect_url`
This commit is contained in:
2026-06-05 17:02:30 +00:00
parent 4ad9334be6
commit 66d91407f5
7 changed files with 31 additions and 9 deletions
+6 -1
View File
@@ -1,3 +1,5 @@
import { Http } from "./Http.js";
export class CommentManager {
constructor() {
this.initCommentReply();
@@ -25,7 +27,10 @@ export class CommentManager {
}
const template = document.getElementById("comment-reply-template");
if (!template) return;
if (!template) {
Http.toLogin();
return;
}
const container = comment.closest(".post-card, .comments-section");
const source = container && container.querySelector(".comment-form:not(.comment-reply-form)");
+9
View File
@@ -1,4 +1,9 @@
export class Http {
static toLogin() {
const next = encodeURIComponent(location.pathname + location.search + location.hash);
window.location.href = `/auth/login?next=${next}`;
}
static async getJson(url) {
const response = await fetch(url);
return response.json();
@@ -13,6 +18,10 @@ export class Http {
},
body: new URLSearchParams(params),
});
if (response.redirected && response.url.includes("/auth/login")) {
Http.toLogin();
return new Promise(() => {});
}
if (!response.ok) {
throw new Error(`request failed with status ${response.status}`);
}