Skip to content

fix: a signed-out visitor to a startup form step is sent to login - #118

Merged
thomgabriel merged 2 commits into
mainfrom
fix/startup-form-logged-out
Oct 2, 2026
Merged

thomgabriel merged 2 commits into
mainfrom
fix/startup-form-logged-out

Conversation

@thomgabriel

Copy link
Copy Markdown
Member

Since #117 the hero only renders on the first screen, so a signed-out person opening /startup-registration?step=4 got an empty page: no form, no login prompt. That is the link the feedback e-mail will use. They are now redirected to /auth?next=/startup-registration?step=4 and come back to the same step. Without a step the page still shows the hero.

Checked on a local server: step 4 signed out answers with the redirect, and the plain page and ?step=done still render the hero.

Since #117 the hero only renders on the first screen, so a signed-out person opening /startup-registration?step=4 from the dashboard or an e-mail got an empty page. They now go to /auth and come back to the same step.
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
hackathon-platform Ready Ready Preview Oct 2, 2026 5:21pm UTC

Request Review

@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Claude finished @thomgabriel's task in 10s —— View job


Safe to merge. No findings.

Checked:

  • Redirect condition: only fires when !state && requested. A plain page and ?step=done still render the hero, and a signed-in user is unaffected.
  • next value: it is built from the whitelisted requested step number and URL-encoded, so there is no open-redirect or injection surface. The auth page and callback read it through pickAuthNext.
  • Redirect position: it runs before any data is rendered, and loadStartup is skipped when there is no state, so no unauthenticated query runs.
  • Conventions: no service-role use, no new copy, and the comment explains why.

The redirect dropped the utm parameters, so a click from an e-mail could not be measured for a signed-out person. They now ride on /auth and inside next.
@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Claude finished @thomgabriel's task in 11s —— View job


Safe to merge. No findings.

Checked: the redirect fires only when !state && requested, so the plain page, ?step=done and signed-in users are unchanged. next is built from the whitelisted step number plus UTM values that are length-capped and URL-encoded, and it goes through pickAuthNext/sanitizeRedirect on the auth side. The redirect runs before any data query. No service-role use, no new copy, and the comment explains why.

@thomgabriel
thomgabriel merged commit 4d906b4 into main Oct 2, 2026
4 checks passed
@thomgabriel
thomgabriel deleted the fix/startup-form-logged-out branch October 2, 2026 17:21

This branch was successfully deployed

1 active deployment
Preview — a68c71f8 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant