mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-08 08:36:37 +08:00
fix(auth): register CAP scope, 400 on captcha, 403 for permission
Navigating from login reused a send_email_code token on register. Captcha failure used 401 so the client stored /register as the post-login target and never left the page. Permission denials now return 403, and the API client no longer wipes the session on 401.
This commit is contained in:
@@ -149,6 +149,16 @@ export function safeRedirectTarget(
|
||||
) {
|
||||
return fallback;
|
||||
}
|
||||
|
||||
if (
|
||||
pathPart === '/login' ||
|
||||
pathPart === '/register' ||
|
||||
pathPart === '/callback' ||
|
||||
pathPart.startsWith('/login/') ||
|
||||
pathPart.startsWith('/register/')
|
||||
) {
|
||||
return fallback;
|
||||
}
|
||||
} catch {
|
||||
return fallback;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user