Skip to content

fix(auth): sanitize login redirect paths - #34

Merged
ralyodio merged 1 commit into
profullstack:masterfrom
rissrice2105-agent:fix/login-redirect-safe
Jul 14, 2026
Merged

ralyodio merged 1 commit into
profullstack:masterfrom
rissrice2105-agent:fix/login-redirect-safe

Conversation

@rissrice2105-agent

Copy link
Copy Markdown
Contributor

Summary

  • add a safeRedirectPath helper for login redirect query params
  • keep internal app paths while falling back external, protocol-relative, missing, or relative values to /dashboard
  • add regression coverage for external redirect sanitization

Tests

  • corepack pnpm --filter @pairux/shared-types build
  • corepack pnpm --filter @pairux/web exec vitest run src/components/auth/LoginForm.test.tsx
  • corepack pnpm --filter @pairux/web typecheck
  • git diff --check

@ralyodio
ralyodio merged commit 1b15778 into profullstack:master Jul 14, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants