Fix OIDC login-gate cross-file wiring bugs from whole-branch review
Four bugs slipped through per-task review since each task only saw its own diff: - Logout was a plain <a href> GET against a POST-only backend route, so it 405'd and never cleared the session cookie or hit Keycloak's end-session redirect. Now a <form method="post"> with a submit button styled to match the old link (still a real full-page navigation, not a fetch, so the Keycloak redirect chain still works). - Login/logout used origin-relative paths, unreachable from the Vite dev server (:5173) against the backend (:8080) with no proxy configured. Both now build their URL from client.ts's now-exported BASE_URL. - handleSessionCallback's four failure paths redirected to /?auth_error=failed with no logging, making a real OIDC failure undiagnosable in production. Added log.Printf on each failure site. - handleSessionLogout passed a bare "/" to EndSessionURL; Keycloak requires post_logout_redirect_uri to be an absolute, registered URL. Added SessionConfig.PublicBaseURL, wired from cfg.PublicBaseURL in main.go, and used to build an absolute redirect. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
import { useEffect, useState } from "react";
|
||||
import { api } from "./api/client";
|
||||
import { api, BASE_URL } from "./api/client";
|
||||
import "./App.css";
|
||||
import { Dashboard } from "./pages/Dashboard";
|
||||
import { Plan } from "./pages/Plan";
|
||||
@@ -56,9 +56,11 @@ function App({ session }: { session: SessionInfo }) {
|
||||
>
|
||||
{profileName ?? "Profile"}
|
||||
</button>
|
||||
<a className="logout-link" href="/api/session/logout" title={session.email}>
|
||||
Log out
|
||||
</a>
|
||||
<form method="post" action={`${BASE_URL}/api/session/logout`} title={session.email}>
|
||||
<button type="submit" className="logout-link">
|
||||
Log out
|
||||
</button>
|
||||
</form>
|
||||
</div>
|
||||
</header>
|
||||
<main>{showProfile ? <Profile onSaved={(p) => setProfileName(p.Name)} /> : <Active />}</main>
|
||||
|
||||
Reference in New Issue
Block a user