Fix login redirection to requested page after authentication #1912
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Problem
When a user attempts to access a protected resource without being logged in, they are correctly redirected to the login page with a
next
parameter preserving their intended destination (e.g.,/?next=%2Fwb0e9nB5T3qecF27Y4xlsg
). However, after successful authentication, the application always redirects to the dashboard/homepage instead of returning the user to their originally requested URL.This creates a poor user experience as users must manually navigate back to the content they were originally trying to access.
Solution
The root cause was identified in the email authentication implementation where the
successReturnToOrRedirect
parameter was hardcoded to always redirect to the server's homepage.This change properly utilizes the
req.session.returnTo
value that's already being correctly set by thesetReturnToFromReferer
function:Testing
Manually tested the authentication flow by:
This fix respects the standard behavior of Passport.js's
successReturnToOrRedirect
parameter, which will redirect to the URL stored inreq.session.returnTo
if available, or fall back to the configured redirect URL otherwise.