Problem
A logged-out member who follows a deep link into the portal loses the destination after login. authenticatedRoute.beforeLoad in nan-cloud-ui/src/router.tsx redirects to /login without carrying the original location, and the magic-link login lands on / afterwards.
This matters for the Workspaces launch: the free-workspace grace notice (cloud-api#311, Spanish lifecycle emails) offers the retention Micro slot. A churned member is usually logged out, so a link to /workspaces/slots?tier=micro drops them on the dashboard after login. They must then find Workspace slots themselves while the grace clock runs.
Expected
/login?next=<path> is set when an unauthenticated member hits an authenticated route (path + search).
- After the magic-link login completes, the member lands on
next.
next is validated: same-origin relative path only (starts with a single /, no //, no scheme), so there is no open redirect.
- The magic-link email/verify flow in cloud-api carries
next through (or the UI keeps it in sessionStorage across the email round trip).
Scope
- NaN community tenant: cloud-ui router + Login page, and the cloud-api magic-link verify redirect if it needs to carry it.
- Tests: open-redirect cases (
//evil.com, https://evil.com, /\evil.com), an unknown path, and a round trip to /workspaces/slots?tier=micro.
Follow-up from the UX/QA review of helmcode/nan-cloud-ui#145.
Problem
A logged-out member who follows a deep link into the portal loses the destination after login.
authenticatedRoute.beforeLoadinnan-cloud-ui/src/router.tsxredirects to/loginwithout carrying the original location, and the magic-link login lands on/afterwards.This matters for the Workspaces launch: the free-workspace grace notice (cloud-api#311, Spanish lifecycle emails) offers the retention Micro slot. A churned member is usually logged out, so a link to
/workspaces/slots?tier=microdrops them on the dashboard after login. They must then find Workspace slots themselves while the grace clock runs.Expected
/login?next=<path>is set when an unauthenticated member hits an authenticated route (path + search).next.nextis validated: same-origin relative path only (starts with a single/, no//, no scheme), so there is no open redirect.nextthrough (or the UI keeps it in sessionStorage across the email round trip).Scope
//evil.com,https://evil.com,/\evil.com), an unknown path, and a round trip to/workspaces/slots?tier=micro.Follow-up from the UX/QA review of helmcode/nan-cloud-ui#145.