fix: user-redirection-when-vote - #726

Closed
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote
Closed

fix: user-redirection-when-vote#726
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote

Conversation

@grv-saini-20

@grv-saini-20grv-saini-20 commented Jan 27, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fixed the issue of redirection to home page instead of to the vote id after user successfully login to evoting.

Issue Number

closes#703

Type of change

  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)

How the change has been tested

Manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Persist and honor post-login redirects (URL param + session storage) so users return to their intended page after sign-in.
  • Bug Fixes

    • Improved authentication event-stream handling and unified redirect resolution across login flows.
    • Minor mobile login text fix.
  • Chores

    • Broad formatting and quote-style standardization.
    • Small typing/format consistency updates and manifest/config reflow (including env var default adjustments).

✏️ Tip: You can customize this high-level summary in your review settings.

@grv-saini-20grv-saini-20 self-assigned this Jan 27, 2026
@grv-saini-20
grv-saini-20 marked this pull request as draft January 27, 2026 09:07
@coderabbitai

coderabbitaiBot commented Jan 27, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Captures redirect query in eVoting login, persists it as postLoginRedirect in sessionStorage, and resolves/clears it after both POST and SSE login flows; SSE effect now depends on redirectTo. Additionally, widespread formatting/quote-style normalization across multiple platform repos and minor Docker Compose env default removals.

Changes

Cohort / File(s)Summary
eVoting Login Redirect Fix
platforms/eVoting/src/app/(auth)/login/page.tsx
Parse redirect query into redirectTo; persist "postLoginRedirect" in sessionStorage; resolve and clear that key after POST and SSE-based login completions; add redirectTo to SSE effect deps; minor mobile UI text fix.
SSE Event Handling (Blabsy)
platforms/blabsy/src/components/login/login-main.tsx
Refactored watchEventStream callback: explicit onopen, onmessage, onerror handlers; separated version-mismatch and token flows; added signInWithCustomToken to useCallback deps.
Control Panel Table Typing
infrastructure/control-panel/src/lib/ui/Table/Table.svelte
Tightened BodyCell snippet typing to Record<string, TableCell<T>>, propagating generic T.
eSigner — Formatting & Utilities
platforms/esigner/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts, src/routes/(protected)/files/[id]/+page.svelte
Quote/style normalization (single→double), indentation/whitespace changes, JSON pretty-printing, and a large reflow of a protected files page; no behavioral changes.
File-Manager — Formatting & Stores
platforms/file-manager/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts
Quote/style normalization and minor string-literal adjustments (e.g., Toast, access permission literals). No behavior changes aside from formatting.
Misc: runtime typing loosened
platforms/dreamSync/client/src/components/auth-modal.tsx
Cast loginSchema / registerSchema to any when passed to zodResolver in useForm (typing loosened; runtime validation unchanged).
Docker Compose: env defaults removed & formatting
docker-compose.core.yml
Reflowed/indented compose file; removed several environment default values (e.g., DATABASE_URL, REGISTRY_DATABASE_URL, PUBLIC_REGISTRY_URL) so they now reference variables without fallbacks; otherwise structural formatting changes only.

Sequence Diagram(s)

sequenceDiagram
participant Browser as Browser (Client)
participant Router as Router
participant AuthAPI as Auth API (POST /login)
participant SSE as SSE Server
participant Storage as sessionStorage
Browser->>AuthAPI: POST /login (auto-login)
AuthAPI-->>Browser: 200 + auth token
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
Note right of Browser: SSE-based flow
Browser->>SSE: open EventSource
SSE-->>Browser: onmessage (token OR version_mismatch)
alt token received
Browser->>AuthAPI: signInWithCustomToken(token)
AuthAPI-->>Browser: auth success
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
else version_mismatch
Browser->>Browser: handle version mismatch (show error/notify)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

bug

Suggested reviewers

  • coodos
  • sosweetham

Poem

🐇 I hopped through code and kept the track,
I cached the path so users come back.
SessionStorage held the post-login key,
SSE sang tokens and set them free,
Now users land where they meant to be. 🎉

🚥 Pre-merge checks | ✅ 3 | ❌ 2
❌ Failed checks (1 warning, 1 inconclusive)
Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 18.18% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Out of Scope Changes check❓ InconclusiveThe majority of changes are formatting-only (quotes, indentation) across multiple platforms. The only functional changes are in eVoting login redirection and minor fixes, all directly supporting the PR objective. Docker-compose environment variable changes appear scoped to configuration.Clarify whether the extensive formatting changes across esigner, file-manager platforms and docker-compose.core.yml environment variable defaults are intentional or should be separated into a distinct formatting/chore PR.
✅ Passed checks (3 passed)
Check nameStatusExplanation
Title check✅ PassedThe PR title 'fix: user-redirection-when-vote' clearly indicates a fix to user redirection related to voting, which aligns with the main objective of fixing the redirect issue after login.
Description check✅ PassedThe PR description includes all required template sections: change description, issue number, type of change, testing method, and completed checklist. The description clearly explains the fix for redirection to vote ID instead of home page.
Linked Issues check✅ PassedThe code changes in login pages implement redirect handling logic that preserves and uses the vote ID from URL parameters when logging in, directly addressing issue #703's requirement for post-login redirection to the specific voting page.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Fix all issues with AI agents
In `@infrastructure/eid-wallet/src/routes/`(app)/scan-qr/+page.svelte:
- Around line 95-100: Remove the debug $effect block that logs
selectedBlindVoteOption to the console; locate the reactive $effect referencing
$selectedBlindVoteOption and delete the entire block (or replace it with a
non-logging dev-only guard around the effect if runtime debugging is needed),
ensuring there are no remaining console.log statements related to
selectedBlindVoteOption.
In `@platforms/eVoting/src/app/`(auth)/login/page.tsx:
- Line 189: Update the typo in the login page JSX where the span reads "Click
the button below using you" to "Click the button below using your"; locate the
span in the login page component (page.tsx) and correct the string literal so
wording matches the desktop version.
- Around line 44-47: The redirect check currently accepts values that start with
"/" which still allows protocol-relative URLs like "//evil.com"; update the
validation where redirect is handled (the conditional using
redirect.startsWith("/") and the subsequent setRedirectTo and
sessionStorage.setItem calls) to explicitly reject protocol-relative paths by
ensuring the second character is not "/" (e.g., require redirect.startsWith("/")
&& redirect[1] !== "/") or validate that redirect is a safe local pathname
(parse and confirm it has no host/authority component) before calling
setRedirectTo and sessionStorage.setItem("postLoginRedirect", ...).
- Around line 137-141: The SSE handler uses the redirectTo state but the
useEffect that registers it does not include redirectTo in its dependency array,
risking a stale closure; update the useEffect that sets up the SSE handler (the
effect that reads sessionStorage.getItem("postLoginRedirect") and calls
window.location.href = redirect) to include redirectTo in its dependency array
so the handler always captures the latest redirectTo value, and ensure any
cleanup/registration logic (the SSE subscription) still runs correctly when
redirectTo changes.
🧹 Nitpick comments (2)
platforms/eVoting/src/app/(auth)/login/page.tsx (2)

44-47: Fix inconsistent indentation.

The code block has inconsistent indentation which affects readability. The if block body should be indented consistently with the surrounding code.

🔧 Proposed fix
 if (redirect && redirect.startsWith("/")) {
- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }

95-99: Fix inconsistent indentation in redirect logic.

Similar to the earlier block, this code has inconsistent indentation that should be corrected for readability and maintainability.

🔧 Proposed fix
 const redirect =
- sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";--sessionStorage.removeItem("postLoginRedirect");-window.location.href = redirect;+ sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";+ sessionStorage.removeItem("postLoginRedirect");+ window.location.href = redirect;

Comment threadinfrastructure/eid-wallet/src/routes/(app)/scan-qr/+page.svelte Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
@grv-saini-20
grv-saini-20 marked this pull request as ready for review January 28, 2026 13:20

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
platforms/eVoting/src/app/(auth)/login/page.tsx (1)

24-47: Persist redirect before early return to avoid losing it in auto-login flows.
If the login page is first opened with ename/session/signature (e.g., a new tab on mobile), the redirect param is ignored because the effect returns before saving it. That can fall back to / even when a redirect was provided.

🐛 Proposed fix
- if (ename && session && signature) {- // Clean up URL- window.history.replaceState({}, '', window.location.pathname);-- // Auto-submit login- handleAutoLogin(ename, session, signature, appVersion || '0.4.0');- return;- }-- if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }++ if (ename && session && signature) {+ // Clean up URL+ window.history.replaceState({}, '', window.location.pathname);++ // Auto-submit login+ handleAutoLogin(ename, session, signature, appVersion || '0.4.0');+ return;+ }
🤖 Fix all issues with AI agents
In `@infrastructure/control-panel/src/lib/ui/Table/Table.svelte`:
- Line 377: The snippet parameter for BodyCell is using the bare Record type
causing a TS error; change the parameter type for data in the BodyCell snippet
to be Record<string, TableCell<T>> (matching the component's generic T and the
TableCell type) so the snippet declaration reads BodyCell(data: Record<string,
TableCell<T>>, field: string, i: number) and aligns with the component generics
and usages of TableCell<T>.

Comment threadinfrastructure/control-panel/src/lib/ui/Table/Table.svelte Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/dreamSync/client/src/components/auth-modal.tsx`:
- Around line 41-43: The useForm call for loginForm is using an unnecessary cast
that disables type inference; remove the "as any" cast on zodResolver so
zodResolver(loginSchema) is passed directly to useForm (loginForm) and let the
resolver infer types from loginSchema; update the same pattern where zodResolver
is used for other forms to drop the "as any" casts.

Comment threadplatforms/dreamSync/client/src/components/auth-modal.tsx

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Fix all issues with AI agents
In `@docker-compose.core.yml`:
- Around line 74-96: Replace the hardcoded default values for the registry
service environment variables so the compose file requires values from .env:
remove the default fallbacks from NODE_ENV, DATABASE_URL, REGISTRY_SHARED_SECRET
and PUBLIC_REGISTRY_URL (use ${NODE_ENV}, ${REGISTRY_DATABASE_URL},
${REGISTRY_SHARED_SECRET}, ${PUBLIC_REGISTRY_URL} respectively), and mirror the
same change for the evault-core service; then update .env.example to document
DATABASE_URL and REGISTRY_SHARED_SECRET (and PUBLIC_REGISTRY_URL) as required
secrets/connection strings so Docker Compose fails if they are not provided.
- Around line 36-72: Remove the hard-coded password from the neo4j service: stop
setting NEO4J_AUTH=neo4j/passkipooski in the environment and instead require a
NEO4J_PASSWORD environment variable (provided via a .env file or env_file kept
out of VCS) and set NEO4J_AUTH from that secret outside the repository; then
update the neo4j healthcheck to perform container-side expansion by invoking a
shell (e.g., change the healthcheck test to use "bash -lc" and reference
"$NEO4J_PASSWORD" inside that command so the password is expanded inside the
container when running cypher-shell) — modify the neo4j service environment and
the healthcheck test (referencing the neo4j service, NEO4J_AUTH/NEO4J_PASSWORD,
and the healthcheck test block) accordingly.

Comment threaddocker-compose.core.yml
Comment threaddocker-compose.core.yml
@coodos

Copy link
Copy Markdown
Contributor

approved at the condition you fix code rabbit suggestions

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

well...

Image

@coodoscoodos closed this Jan 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] User is redirected to home page instead of vote after login from chat

2 participants

@grv-saini-20@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: user-redirection-when-vote - #726

Closed
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote
Closed

fix: user-redirection-when-vote#726
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote

Conversation

@grv-saini-20

@grv-saini-20grv-saini-20 commented Jan 27, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fixed the issue of redirection to home page instead of to the vote id after user successfully login to evoting.

Issue Number

closes#703

Type of change

  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)

How the change has been tested

Manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Persist and honor post-login redirects (URL param + session storage) so users return to their intended page after sign-in.
  • Bug Fixes

    • Improved authentication event-stream handling and unified redirect resolution across login flows.
    • Minor mobile login text fix.
  • Chores

    • Broad formatting and quote-style standardization.
    • Small typing/format consistency updates and manifest/config reflow (including env var default adjustments).

✏️ Tip: You can customize this high-level summary in your review settings.

@grv-saini-20grv-saini-20 self-assigned this Jan 27, 2026
@grv-saini-20
grv-saini-20 marked this pull request as draft January 27, 2026 09:07
@coderabbitai

coderabbitaiBot commented Jan 27, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Captures redirect query in eVoting login, persists it as postLoginRedirect in sessionStorage, and resolves/clears it after both POST and SSE login flows; SSE effect now depends on redirectTo. Additionally, widespread formatting/quote-style normalization across multiple platform repos and minor Docker Compose env default removals.

Changes

Cohort / File(s)Summary
eVoting Login Redirect Fix
platforms/eVoting/src/app/(auth)/login/page.tsx
Parse redirect query into redirectTo; persist "postLoginRedirect" in sessionStorage; resolve and clear that key after POST and SSE-based login completions; add redirectTo to SSE effect deps; minor mobile UI text fix.
SSE Event Handling (Blabsy)
platforms/blabsy/src/components/login/login-main.tsx
Refactored watchEventStream callback: explicit onopen, onmessage, onerror handlers; separated version-mismatch and token flows; added signInWithCustomToken to useCallback deps.
Control Panel Table Typing
infrastructure/control-panel/src/lib/ui/Table/Table.svelte
Tightened BodyCell snippet typing to Record<string, TableCell<T>>, propagating generic T.
eSigner — Formatting & Utilities
platforms/esigner/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts, src/routes/(protected)/files/[id]/+page.svelte
Quote/style normalization (single→double), indentation/whitespace changes, JSON pretty-printing, and a large reflow of a protected files page; no behavioral changes.
File-Manager — Formatting & Stores
platforms/file-manager/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts
Quote/style normalization and minor string-literal adjustments (e.g., Toast, access permission literals). No behavior changes aside from formatting.
Misc: runtime typing loosened
platforms/dreamSync/client/src/components/auth-modal.tsx
Cast loginSchema / registerSchema to any when passed to zodResolver in useForm (typing loosened; runtime validation unchanged).
Docker Compose: env defaults removed & formatting
docker-compose.core.yml
Reflowed/indented compose file; removed several environment default values (e.g., DATABASE_URL, REGISTRY_DATABASE_URL, PUBLIC_REGISTRY_URL) so they now reference variables without fallbacks; otherwise structural formatting changes only.

Sequence Diagram(s)

sequenceDiagram
participant Browser as Browser (Client)
participant Router as Router
participant AuthAPI as Auth API (POST /login)
participant SSE as SSE Server
participant Storage as sessionStorage
Browser->>AuthAPI: POST /login (auto-login)
AuthAPI-->>Browser: 200 + auth token
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
Note right of Browser: SSE-based flow
Browser->>SSE: open EventSource
SSE-->>Browser: onmessage (token OR version_mismatch)
alt token received
Browser->>AuthAPI: signInWithCustomToken(token)
AuthAPI-->>Browser: auth success
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
else version_mismatch
Browser->>Browser: handle version mismatch (show error/notify)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

bug

Suggested reviewers

  • coodos
  • sosweetham

Poem

🐇 I hopped through code and kept the track,
I cached the path so users come back.
SessionStorage held the post-login key,
SSE sang tokens and set them free,
Now users land where they meant to be. 🎉

🚥 Pre-merge checks | ✅ 3 | ❌ 2
❌ Failed checks (1 warning, 1 inconclusive)
Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 18.18% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Out of Scope Changes check❓ InconclusiveThe majority of changes are formatting-only (quotes, indentation) across multiple platforms. The only functional changes are in eVoting login redirection and minor fixes, all directly supporting the PR objective. Docker-compose environment variable changes appear scoped to configuration.Clarify whether the extensive formatting changes across esigner, file-manager platforms and docker-compose.core.yml environment variable defaults are intentional or should be separated into a distinct formatting/chore PR.
✅ Passed checks (3 passed)
Check nameStatusExplanation
Title check✅ PassedThe PR title 'fix: user-redirection-when-vote' clearly indicates a fix to user redirection related to voting, which aligns with the main objective of fixing the redirect issue after login.
Description check✅ PassedThe PR description includes all required template sections: change description, issue number, type of change, testing method, and completed checklist. The description clearly explains the fix for redirection to vote ID instead of home page.
Linked Issues check✅ PassedThe code changes in login pages implement redirect handling logic that preserves and uses the vote ID from URL parameters when logging in, directly addressing issue #703's requirement for post-login redirection to the specific voting page.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Fix all issues with AI agents
In `@infrastructure/eid-wallet/src/routes/`(app)/scan-qr/+page.svelte:
- Around line 95-100: Remove the debug $effect block that logs
selectedBlindVoteOption to the console; locate the reactive $effect referencing
$selectedBlindVoteOption and delete the entire block (or replace it with a
non-logging dev-only guard around the effect if runtime debugging is needed),
ensuring there are no remaining console.log statements related to
selectedBlindVoteOption.
In `@platforms/eVoting/src/app/`(auth)/login/page.tsx:
- Line 189: Update the typo in the login page JSX where the span reads "Click
the button below using you" to "Click the button below using your"; locate the
span in the login page component (page.tsx) and correct the string literal so
wording matches the desktop version.
- Around line 44-47: The redirect check currently accepts values that start with
"/" which still allows protocol-relative URLs like "//evil.com"; update the
validation where redirect is handled (the conditional using
redirect.startsWith("/") and the subsequent setRedirectTo and
sessionStorage.setItem calls) to explicitly reject protocol-relative paths by
ensuring the second character is not "/" (e.g., require redirect.startsWith("/")
&& redirect[1] !== "/") or validate that redirect is a safe local pathname
(parse and confirm it has no host/authority component) before calling
setRedirectTo and sessionStorage.setItem("postLoginRedirect", ...).
- Around line 137-141: The SSE handler uses the redirectTo state but the
useEffect that registers it does not include redirectTo in its dependency array,
risking a stale closure; update the useEffect that sets up the SSE handler (the
effect that reads sessionStorage.getItem("postLoginRedirect") and calls
window.location.href = redirect) to include redirectTo in its dependency array
so the handler always captures the latest redirectTo value, and ensure any
cleanup/registration logic (the SSE subscription) still runs correctly when
redirectTo changes.
🧹 Nitpick comments (2)
platforms/eVoting/src/app/(auth)/login/page.tsx (2)

44-47: Fix inconsistent indentation.

The code block has inconsistent indentation which affects readability. The if block body should be indented consistently with the surrounding code.

🔧 Proposed fix
 if (redirect && redirect.startsWith("/")) {
- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }

95-99: Fix inconsistent indentation in redirect logic.

Similar to the earlier block, this code has inconsistent indentation that should be corrected for readability and maintainability.

🔧 Proposed fix
 const redirect =
- sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";--sessionStorage.removeItem("postLoginRedirect");-window.location.href = redirect;+ sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";+ sessionStorage.removeItem("postLoginRedirect");+ window.location.href = redirect;

Comment threadinfrastructure/eid-wallet/src/routes/(app)/scan-qr/+page.svelte Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
@grv-saini-20
grv-saini-20 marked this pull request as ready for review January 28, 2026 13:20

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
platforms/eVoting/src/app/(auth)/login/page.tsx (1)

24-47: Persist redirect before early return to avoid losing it in auto-login flows.
If the login page is first opened with ename/session/signature (e.g., a new tab on mobile), the redirect param is ignored because the effect returns before saving it. That can fall back to / even when a redirect was provided.

🐛 Proposed fix
- if (ename && session && signature) {- // Clean up URL- window.history.replaceState({}, '', window.location.pathname);-- // Auto-submit login- handleAutoLogin(ename, session, signature, appVersion || '0.4.0');- return;- }-- if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }++ if (ename && session && signature) {+ // Clean up URL+ window.history.replaceState({}, '', window.location.pathname);++ // Auto-submit login+ handleAutoLogin(ename, session, signature, appVersion || '0.4.0');+ return;+ }
🤖 Fix all issues with AI agents
In `@infrastructure/control-panel/src/lib/ui/Table/Table.svelte`:
- Line 377: The snippet parameter for BodyCell is using the bare Record type
causing a TS error; change the parameter type for data in the BodyCell snippet
to be Record<string, TableCell<T>> (matching the component's generic T and the
TableCell type) so the snippet declaration reads BodyCell(data: Record<string,
TableCell<T>>, field: string, i: number) and aligns with the component generics
and usages of TableCell<T>.

Comment threadinfrastructure/control-panel/src/lib/ui/Table/Table.svelte Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/dreamSync/client/src/components/auth-modal.tsx`:
- Around line 41-43: The useForm call for loginForm is using an unnecessary cast
that disables type inference; remove the "as any" cast on zodResolver so
zodResolver(loginSchema) is passed directly to useForm (loginForm) and let the
resolver infer types from loginSchema; update the same pattern where zodResolver
is used for other forms to drop the "as any" casts.

Comment threadplatforms/dreamSync/client/src/components/auth-modal.tsx

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Fix all issues with AI agents
In `@docker-compose.core.yml`:
- Around line 74-96: Replace the hardcoded default values for the registry
service environment variables so the compose file requires values from .env:
remove the default fallbacks from NODE_ENV, DATABASE_URL, REGISTRY_SHARED_SECRET
and PUBLIC_REGISTRY_URL (use ${NODE_ENV}, ${REGISTRY_DATABASE_URL},
${REGISTRY_SHARED_SECRET}, ${PUBLIC_REGISTRY_URL} respectively), and mirror the
same change for the evault-core service; then update .env.example to document
DATABASE_URL and REGISTRY_SHARED_SECRET (and PUBLIC_REGISTRY_URL) as required
secrets/connection strings so Docker Compose fails if they are not provided.
- Around line 36-72: Remove the hard-coded password from the neo4j service: stop
setting NEO4J_AUTH=neo4j/passkipooski in the environment and instead require a
NEO4J_PASSWORD environment variable (provided via a .env file or env_file kept
out of VCS) and set NEO4J_AUTH from that secret outside the repository; then
update the neo4j healthcheck to perform container-side expansion by invoking a
shell (e.g., change the healthcheck test to use "bash -lc" and reference
"$NEO4J_PASSWORD" inside that command so the password is expanded inside the
container when running cypher-shell) — modify the neo4j service environment and
the healthcheck test (referencing the neo4j service, NEO4J_AUTH/NEO4J_PASSWORD,
and the healthcheck test block) accordingly.

Comment threaddocker-compose.core.yml
Comment threaddocker-compose.core.yml
@coodos

Copy link
Copy Markdown
Contributor

approved at the condition you fix code rabbit suggestions

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

well...

Image

@coodoscoodos closed this Jan 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] User is redirected to home page instead of vote after login from chat

2 participants

@grv-saini-20@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: user-redirection-when-vote - #726

Closed
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote
Closed

fix: user-redirection-when-vote#726
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote

Conversation

@grv-saini-20

@grv-saini-20grv-saini-20 commented Jan 27, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fixed the issue of redirection to home page instead of to the vote id after user successfully login to evoting.

Issue Number

closes#703

Type of change

  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)

How the change has been tested

Manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Persist and honor post-login redirects (URL param + session storage) so users return to their intended page after sign-in.
  • Bug Fixes

    • Improved authentication event-stream handling and unified redirect resolution across login flows.
    • Minor mobile login text fix.
  • Chores

    • Broad formatting and quote-style standardization.
    • Small typing/format consistency updates and manifest/config reflow (including env var default adjustments).

✏️ Tip: You can customize this high-level summary in your review settings.

@grv-saini-20grv-saini-20 self-assigned this Jan 27, 2026
@grv-saini-20
grv-saini-20 marked this pull request as draft January 27, 2026 09:07
@coderabbitai

coderabbitaiBot commented Jan 27, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Captures redirect query in eVoting login, persists it as postLoginRedirect in sessionStorage, and resolves/clears it after both POST and SSE login flows; SSE effect now depends on redirectTo. Additionally, widespread formatting/quote-style normalization across multiple platform repos and minor Docker Compose env default removals.

Changes

Cohort / File(s)Summary
eVoting Login Redirect Fix
platforms/eVoting/src/app/(auth)/login/page.tsx
Parse redirect query into redirectTo; persist "postLoginRedirect" in sessionStorage; resolve and clear that key after POST and SSE-based login completions; add redirectTo to SSE effect deps; minor mobile UI text fix.
SSE Event Handling (Blabsy)
platforms/blabsy/src/components/login/login-main.tsx
Refactored watchEventStream callback: explicit onopen, onmessage, onerror handlers; separated version-mismatch and token flows; added signInWithCustomToken to useCallback deps.
Control Panel Table Typing
infrastructure/control-panel/src/lib/ui/Table/Table.svelte
Tightened BodyCell snippet typing to Record<string, TableCell<T>>, propagating generic T.
eSigner — Formatting & Utilities
platforms/esigner/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts, src/routes/(protected)/files/[id]/+page.svelte
Quote/style normalization (single→double), indentation/whitespace changes, JSON pretty-printing, and a large reflow of a protected files page; no behavioral changes.
File-Manager — Formatting & Stores
platforms/file-manager/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts
Quote/style normalization and minor string-literal adjustments (e.g., Toast, access permission literals). No behavior changes aside from formatting.
Misc: runtime typing loosened
platforms/dreamSync/client/src/components/auth-modal.tsx
Cast loginSchema / registerSchema to any when passed to zodResolver in useForm (typing loosened; runtime validation unchanged).
Docker Compose: env defaults removed & formatting
docker-compose.core.yml
Reflowed/indented compose file; removed several environment default values (e.g., DATABASE_URL, REGISTRY_DATABASE_URL, PUBLIC_REGISTRY_URL) so they now reference variables without fallbacks; otherwise structural formatting changes only.

Sequence Diagram(s)

sequenceDiagram
participant Browser as Browser (Client)
participant Router as Router
participant AuthAPI as Auth API (POST /login)
participant SSE as SSE Server
participant Storage as sessionStorage
Browser->>AuthAPI: POST /login (auto-login)
AuthAPI-->>Browser: 200 + auth token
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
Note right of Browser: SSE-based flow
Browser->>SSE: open EventSource
SSE-->>Browser: onmessage (token OR version_mismatch)
alt token received
Browser->>AuthAPI: signInWithCustomToken(token)
AuthAPI-->>Browser: auth success
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
else version_mismatch
Browser->>Browser: handle version mismatch (show error/notify)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

bug

Suggested reviewers

  • coodos
  • sosweetham

Poem

🐇 I hopped through code and kept the track,
I cached the path so users come back.
SessionStorage held the post-login key,
SSE sang tokens and set them free,
Now users land where they meant to be. 🎉

🚥 Pre-merge checks | ✅ 3 | ❌ 2
❌ Failed checks (1 warning, 1 inconclusive)
Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 18.18% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Out of Scope Changes check❓ InconclusiveThe majority of changes are formatting-only (quotes, indentation) across multiple platforms. The only functional changes are in eVoting login redirection and minor fixes, all directly supporting the PR objective. Docker-compose environment variable changes appear scoped to configuration.Clarify whether the extensive formatting changes across esigner, file-manager platforms and docker-compose.core.yml environment variable defaults are intentional or should be separated into a distinct formatting/chore PR.
✅ Passed checks (3 passed)
Check nameStatusExplanation
Title check✅ PassedThe PR title 'fix: user-redirection-when-vote' clearly indicates a fix to user redirection related to voting, which aligns with the main objective of fixing the redirect issue after login.
Description check✅ PassedThe PR description includes all required template sections: change description, issue number, type of change, testing method, and completed checklist. The description clearly explains the fix for redirection to vote ID instead of home page.
Linked Issues check✅ PassedThe code changes in login pages implement redirect handling logic that preserves and uses the vote ID from URL parameters when logging in, directly addressing issue #703's requirement for post-login redirection to the specific voting page.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Fix all issues with AI agents
In `@infrastructure/eid-wallet/src/routes/`(app)/scan-qr/+page.svelte:
- Around line 95-100: Remove the debug $effect block that logs
selectedBlindVoteOption to the console; locate the reactive $effect referencing
$selectedBlindVoteOption and delete the entire block (or replace it with a
non-logging dev-only guard around the effect if runtime debugging is needed),
ensuring there are no remaining console.log statements related to
selectedBlindVoteOption.
In `@platforms/eVoting/src/app/`(auth)/login/page.tsx:
- Line 189: Update the typo in the login page JSX where the span reads "Click
the button below using you" to "Click the button below using your"; locate the
span in the login page component (page.tsx) and correct the string literal so
wording matches the desktop version.
- Around line 44-47: The redirect check currently accepts values that start with
"/" which still allows protocol-relative URLs like "//evil.com"; update the
validation where redirect is handled (the conditional using
redirect.startsWith("/") and the subsequent setRedirectTo and
sessionStorage.setItem calls) to explicitly reject protocol-relative paths by
ensuring the second character is not "/" (e.g., require redirect.startsWith("/")
&& redirect[1] !== "/") or validate that redirect is a safe local pathname
(parse and confirm it has no host/authority component) before calling
setRedirectTo and sessionStorage.setItem("postLoginRedirect", ...).
- Around line 137-141: The SSE handler uses the redirectTo state but the
useEffect that registers it does not include redirectTo in its dependency array,
risking a stale closure; update the useEffect that sets up the SSE handler (the
effect that reads sessionStorage.getItem("postLoginRedirect") and calls
window.location.href = redirect) to include redirectTo in its dependency array
so the handler always captures the latest redirectTo value, and ensure any
cleanup/registration logic (the SSE subscription) still runs correctly when
redirectTo changes.
🧹 Nitpick comments (2)
platforms/eVoting/src/app/(auth)/login/page.tsx (2)

44-47: Fix inconsistent indentation.

The code block has inconsistent indentation which affects readability. The if block body should be indented consistently with the surrounding code.

🔧 Proposed fix
 if (redirect && redirect.startsWith("/")) {
- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }

95-99: Fix inconsistent indentation in redirect logic.

Similar to the earlier block, this code has inconsistent indentation that should be corrected for readability and maintainability.

🔧 Proposed fix
 const redirect =
- sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";--sessionStorage.removeItem("postLoginRedirect");-window.location.href = redirect;+ sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";+ sessionStorage.removeItem("postLoginRedirect");+ window.location.href = redirect;

Comment threadinfrastructure/eid-wallet/src/routes/(app)/scan-qr/+page.svelte Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
@grv-saini-20
grv-saini-20 marked this pull request as ready for review January 28, 2026 13:20

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
platforms/eVoting/src/app/(auth)/login/page.tsx (1)

24-47: Persist redirect before early return to avoid losing it in auto-login flows.
If the login page is first opened with ename/session/signature (e.g., a new tab on mobile), the redirect param is ignored because the effect returns before saving it. That can fall back to / even when a redirect was provided.

🐛 Proposed fix
- if (ename && session && signature) {- // Clean up URL- window.history.replaceState({}, '', window.location.pathname);-- // Auto-submit login- handleAutoLogin(ename, session, signature, appVersion || '0.4.0');- return;- }-- if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }++ if (ename && session && signature) {+ // Clean up URL+ window.history.replaceState({}, '', window.location.pathname);++ // Auto-submit login+ handleAutoLogin(ename, session, signature, appVersion || '0.4.0');+ return;+ }
🤖 Fix all issues with AI agents
In `@infrastructure/control-panel/src/lib/ui/Table/Table.svelte`:
- Line 377: The snippet parameter for BodyCell is using the bare Record type
causing a TS error; change the parameter type for data in the BodyCell snippet
to be Record<string, TableCell<T>> (matching the component's generic T and the
TableCell type) so the snippet declaration reads BodyCell(data: Record<string,
TableCell<T>>, field: string, i: number) and aligns with the component generics
and usages of TableCell<T>.

Comment threadinfrastructure/control-panel/src/lib/ui/Table/Table.svelte Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/dreamSync/client/src/components/auth-modal.tsx`:
- Around line 41-43: The useForm call for loginForm is using an unnecessary cast
that disables type inference; remove the "as any" cast on zodResolver so
zodResolver(loginSchema) is passed directly to useForm (loginForm) and let the
resolver infer types from loginSchema; update the same pattern where zodResolver
is used for other forms to drop the "as any" casts.

Comment threadplatforms/dreamSync/client/src/components/auth-modal.tsx

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Fix all issues with AI agents
In `@docker-compose.core.yml`:
- Around line 74-96: Replace the hardcoded default values for the registry
service environment variables so the compose file requires values from .env:
remove the default fallbacks from NODE_ENV, DATABASE_URL, REGISTRY_SHARED_SECRET
and PUBLIC_REGISTRY_URL (use ${NODE_ENV}, ${REGISTRY_DATABASE_URL},
${REGISTRY_SHARED_SECRET}, ${PUBLIC_REGISTRY_URL} respectively), and mirror the
same change for the evault-core service; then update .env.example to document
DATABASE_URL and REGISTRY_SHARED_SECRET (and PUBLIC_REGISTRY_URL) as required
secrets/connection strings so Docker Compose fails if they are not provided.
- Around line 36-72: Remove the hard-coded password from the neo4j service: stop
setting NEO4J_AUTH=neo4j/passkipooski in the environment and instead require a
NEO4J_PASSWORD environment variable (provided via a .env file or env_file kept
out of VCS) and set NEO4J_AUTH from that secret outside the repository; then
update the neo4j healthcheck to perform container-side expansion by invoking a
shell (e.g., change the healthcheck test to use "bash -lc" and reference
"$NEO4J_PASSWORD" inside that command so the password is expanded inside the
container when running cypher-shell) — modify the neo4j service environment and
the healthcheck test (referencing the neo4j service, NEO4J_AUTH/NEO4J_PASSWORD,
and the healthcheck test block) accordingly.

Comment threaddocker-compose.core.yml
Comment threaddocker-compose.core.yml
@coodos

Copy link
Copy Markdown
Contributor

approved at the condition you fix code rabbit suggestions

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

well...

Image

@coodoscoodos closed this Jan 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] User is redirected to home page instead of vote after login from chat

2 participants

@grv-saini-20@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: user-redirection-when-vote - #726

Closed
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote
Closed

fix: user-redirection-when-vote#726
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote

Conversation

@grv-saini-20

@grv-saini-20grv-saini-20 commented Jan 27, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fixed the issue of redirection to home page instead of to the vote id after user successfully login to evoting.

Issue Number

closes#703

Type of change

  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)

How the change has been tested

Manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Persist and honor post-login redirects (URL param + session storage) so users return to their intended page after sign-in.
  • Bug Fixes

    • Improved authentication event-stream handling and unified redirect resolution across login flows.
    • Minor mobile login text fix.
  • Chores

    • Broad formatting and quote-style standardization.
    • Small typing/format consistency updates and manifest/config reflow (including env var default adjustments).

✏️ Tip: You can customize this high-level summary in your review settings.

@grv-saini-20grv-saini-20 self-assigned this Jan 27, 2026
@grv-saini-20
grv-saini-20 marked this pull request as draft January 27, 2026 09:07
@coderabbitai

coderabbitaiBot commented Jan 27, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Captures redirect query in eVoting login, persists it as postLoginRedirect in sessionStorage, and resolves/clears it after both POST and SSE login flows; SSE effect now depends on redirectTo. Additionally, widespread formatting/quote-style normalization across multiple platform repos and minor Docker Compose env default removals.

Changes

Cohort / File(s)Summary
eVoting Login Redirect Fix
platforms/eVoting/src/app/(auth)/login/page.tsx
Parse redirect query into redirectTo; persist "postLoginRedirect" in sessionStorage; resolve and clear that key after POST and SSE-based login completions; add redirectTo to SSE effect deps; minor mobile UI text fix.
SSE Event Handling (Blabsy)
platforms/blabsy/src/components/login/login-main.tsx
Refactored watchEventStream callback: explicit onopen, onmessage, onerror handlers; separated version-mismatch and token flows; added signInWithCustomToken to useCallback deps.
Control Panel Table Typing
infrastructure/control-panel/src/lib/ui/Table/Table.svelte
Tightened BodyCell snippet typing to Record<string, TableCell<T>>, propagating generic T.
eSigner — Formatting & Utilities
platforms/esigner/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts, src/routes/(protected)/files/[id]/+page.svelte
Quote/style normalization (single→double), indentation/whitespace changes, JSON pretty-printing, and a large reflow of a protected files page; no behavioral changes.
File-Manager — Formatting & Stores
platforms/file-manager/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts
Quote/style normalization and minor string-literal adjustments (e.g., Toast, access permission literals). No behavior changes aside from formatting.
Misc: runtime typing loosened
platforms/dreamSync/client/src/components/auth-modal.tsx
Cast loginSchema / registerSchema to any when passed to zodResolver in useForm (typing loosened; runtime validation unchanged).
Docker Compose: env defaults removed & formatting
docker-compose.core.yml
Reflowed/indented compose file; removed several environment default values (e.g., DATABASE_URL, REGISTRY_DATABASE_URL, PUBLIC_REGISTRY_URL) so they now reference variables without fallbacks; otherwise structural formatting changes only.

Sequence Diagram(s)

sequenceDiagram
participant Browser as Browser (Client)
participant Router as Router
participant AuthAPI as Auth API (POST /login)
participant SSE as SSE Server
participant Storage as sessionStorage
Browser->>AuthAPI: POST /login (auto-login)
AuthAPI-->>Browser: 200 + auth token
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
Note right of Browser: SSE-based flow
Browser->>SSE: open EventSource
SSE-->>Browser: onmessage (token OR version_mismatch)
alt token received
Browser->>AuthAPI: signInWithCustomToken(token)
AuthAPI-->>Browser: auth success
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
else version_mismatch
Browser->>Browser: handle version mismatch (show error/notify)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

bug

Suggested reviewers

  • coodos
  • sosweetham

Poem

🐇 I hopped through code and kept the track,
I cached the path so users come back.
SessionStorage held the post-login key,
SSE sang tokens and set them free,
Now users land where they meant to be. 🎉

🚥 Pre-merge checks | ✅ 3 | ❌ 2
❌ Failed checks (1 warning, 1 inconclusive)
Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 18.18% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Out of Scope Changes check❓ InconclusiveThe majority of changes are formatting-only (quotes, indentation) across multiple platforms. The only functional changes are in eVoting login redirection and minor fixes, all directly supporting the PR objective. Docker-compose environment variable changes appear scoped to configuration.Clarify whether the extensive formatting changes across esigner, file-manager platforms and docker-compose.core.yml environment variable defaults are intentional or should be separated into a distinct formatting/chore PR.
✅ Passed checks (3 passed)
Check nameStatusExplanation
Title check✅ PassedThe PR title 'fix: user-redirection-when-vote' clearly indicates a fix to user redirection related to voting, which aligns with the main objective of fixing the redirect issue after login.
Description check✅ PassedThe PR description includes all required template sections: change description, issue number, type of change, testing method, and completed checklist. The description clearly explains the fix for redirection to vote ID instead of home page.
Linked Issues check✅ PassedThe code changes in login pages implement redirect handling logic that preserves and uses the vote ID from URL parameters when logging in, directly addressing issue #703's requirement for post-login redirection to the specific voting page.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Fix all issues with AI agents
In `@infrastructure/eid-wallet/src/routes/`(app)/scan-qr/+page.svelte:
- Around line 95-100: Remove the debug $effect block that logs
selectedBlindVoteOption to the console; locate the reactive $effect referencing
$selectedBlindVoteOption and delete the entire block (or replace it with a
non-logging dev-only guard around the effect if runtime debugging is needed),
ensuring there are no remaining console.log statements related to
selectedBlindVoteOption.
In `@platforms/eVoting/src/app/`(auth)/login/page.tsx:
- Line 189: Update the typo in the login page JSX where the span reads "Click
the button below using you" to "Click the button below using your"; locate the
span in the login page component (page.tsx) and correct the string literal so
wording matches the desktop version.
- Around line 44-47: The redirect check currently accepts values that start with
"/" which still allows protocol-relative URLs like "//evil.com"; update the
validation where redirect is handled (the conditional using
redirect.startsWith("/") and the subsequent setRedirectTo and
sessionStorage.setItem calls) to explicitly reject protocol-relative paths by
ensuring the second character is not "/" (e.g., require redirect.startsWith("/")
&& redirect[1] !== "/") or validate that redirect is a safe local pathname
(parse and confirm it has no host/authority component) before calling
setRedirectTo and sessionStorage.setItem("postLoginRedirect", ...).
- Around line 137-141: The SSE handler uses the redirectTo state but the
useEffect that registers it does not include redirectTo in its dependency array,
risking a stale closure; update the useEffect that sets up the SSE handler (the
effect that reads sessionStorage.getItem("postLoginRedirect") and calls
window.location.href = redirect) to include redirectTo in its dependency array
so the handler always captures the latest redirectTo value, and ensure any
cleanup/registration logic (the SSE subscription) still runs correctly when
redirectTo changes.
🧹 Nitpick comments (2)
platforms/eVoting/src/app/(auth)/login/page.tsx (2)

44-47: Fix inconsistent indentation.

The code block has inconsistent indentation which affects readability. The if block body should be indented consistently with the surrounding code.

🔧 Proposed fix
 if (redirect && redirect.startsWith("/")) {
- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }

95-99: Fix inconsistent indentation in redirect logic.

Similar to the earlier block, this code has inconsistent indentation that should be corrected for readability and maintainability.

🔧 Proposed fix
 const redirect =
- sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";--sessionStorage.removeItem("postLoginRedirect");-window.location.href = redirect;+ sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";+ sessionStorage.removeItem("postLoginRedirect");+ window.location.href = redirect;

Comment threadinfrastructure/eid-wallet/src/routes/(app)/scan-qr/+page.svelte Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
@grv-saini-20
grv-saini-20 marked this pull request as ready for review January 28, 2026 13:20

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
platforms/eVoting/src/app/(auth)/login/page.tsx (1)

24-47: Persist redirect before early return to avoid losing it in auto-login flows.
If the login page is first opened with ename/session/signature (e.g., a new tab on mobile), the redirect param is ignored because the effect returns before saving it. That can fall back to / even when a redirect was provided.

🐛 Proposed fix
- if (ename && session && signature) {- // Clean up URL- window.history.replaceState({}, '', window.location.pathname);-- // Auto-submit login- handleAutoLogin(ename, session, signature, appVersion || '0.4.0');- return;- }-- if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }++ if (ename && session && signature) {+ // Clean up URL+ window.history.replaceState({}, '', window.location.pathname);++ // Auto-submit login+ handleAutoLogin(ename, session, signature, appVersion || '0.4.0');+ return;+ }
🤖 Fix all issues with AI agents
In `@infrastructure/control-panel/src/lib/ui/Table/Table.svelte`:
- Line 377: The snippet parameter for BodyCell is using the bare Record type
causing a TS error; change the parameter type for data in the BodyCell snippet
to be Record<string, TableCell<T>> (matching the component's generic T and the
TableCell type) so the snippet declaration reads BodyCell(data: Record<string,
TableCell<T>>, field: string, i: number) and aligns with the component generics
and usages of TableCell<T>.

Comment threadinfrastructure/control-panel/src/lib/ui/Table/Table.svelte Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/dreamSync/client/src/components/auth-modal.tsx`:
- Around line 41-43: The useForm call for loginForm is using an unnecessary cast
that disables type inference; remove the "as any" cast on zodResolver so
zodResolver(loginSchema) is passed directly to useForm (loginForm) and let the
resolver infer types from loginSchema; update the same pattern where zodResolver
is used for other forms to drop the "as any" casts.

Comment threadplatforms/dreamSync/client/src/components/auth-modal.tsx

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Fix all issues with AI agents
In `@docker-compose.core.yml`:
- Around line 74-96: Replace the hardcoded default values for the registry
service environment variables so the compose file requires values from .env:
remove the default fallbacks from NODE_ENV, DATABASE_URL, REGISTRY_SHARED_SECRET
and PUBLIC_REGISTRY_URL (use ${NODE_ENV}, ${REGISTRY_DATABASE_URL},
${REGISTRY_SHARED_SECRET}, ${PUBLIC_REGISTRY_URL} respectively), and mirror the
same change for the evault-core service; then update .env.example to document
DATABASE_URL and REGISTRY_SHARED_SECRET (and PUBLIC_REGISTRY_URL) as required
secrets/connection strings so Docker Compose fails if they are not provided.
- Around line 36-72: Remove the hard-coded password from the neo4j service: stop
setting NEO4J_AUTH=neo4j/passkipooski in the environment and instead require a
NEO4J_PASSWORD environment variable (provided via a .env file or env_file kept
out of VCS) and set NEO4J_AUTH from that secret outside the repository; then
update the neo4j healthcheck to perform container-side expansion by invoking a
shell (e.g., change the healthcheck test to use "bash -lc" and reference
"$NEO4J_PASSWORD" inside that command so the password is expanded inside the
container when running cypher-shell) — modify the neo4j service environment and
the healthcheck test (referencing the neo4j service, NEO4J_AUTH/NEO4J_PASSWORD,
and the healthcheck test block) accordingly.

Comment threaddocker-compose.core.yml
Comment threaddocker-compose.core.yml
@coodos

Copy link
Copy Markdown
Contributor

approved at the condition you fix code rabbit suggestions

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

well...

Image

@coodoscoodos closed this Jan 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] User is redirected to home page instead of vote after login from chat

2 participants

@grv-saini-20@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: user-redirection-when-vote - #726

Closed
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote
Closed

fix: user-redirection-when-vote#726
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote

Conversation

@grv-saini-20

@grv-saini-20grv-saini-20 commented Jan 27, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fixed the issue of redirection to home page instead of to the vote id after user successfully login to evoting.

Issue Number

closes#703

Type of change

  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)

How the change has been tested

Manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Persist and honor post-login redirects (URL param + session storage) so users return to their intended page after sign-in.
  • Bug Fixes

    • Improved authentication event-stream handling and unified redirect resolution across login flows.
    • Minor mobile login text fix.
  • Chores

    • Broad formatting and quote-style standardization.
    • Small typing/format consistency updates and manifest/config reflow (including env var default adjustments).

✏️ Tip: You can customize this high-level summary in your review settings.

@grv-saini-20grv-saini-20 self-assigned this Jan 27, 2026
@grv-saini-20
grv-saini-20 marked this pull request as draft January 27, 2026 09:07
@coderabbitai

coderabbitaiBot commented Jan 27, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Captures redirect query in eVoting login, persists it as postLoginRedirect in sessionStorage, and resolves/clears it after both POST and SSE login flows; SSE effect now depends on redirectTo. Additionally, widespread formatting/quote-style normalization across multiple platform repos and minor Docker Compose env default removals.

Changes

Cohort / File(s)Summary
eVoting Login Redirect Fix
platforms/eVoting/src/app/(auth)/login/page.tsx
Parse redirect query into redirectTo; persist "postLoginRedirect" in sessionStorage; resolve and clear that key after POST and SSE-based login completions; add redirectTo to SSE effect deps; minor mobile UI text fix.
SSE Event Handling (Blabsy)
platforms/blabsy/src/components/login/login-main.tsx
Refactored watchEventStream callback: explicit onopen, onmessage, onerror handlers; separated version-mismatch and token flows; added signInWithCustomToken to useCallback deps.
Control Panel Table Typing
infrastructure/control-panel/src/lib/ui/Table/Table.svelte
Tightened BodyCell snippet typing to Record<string, TableCell<T>>, propagating generic T.
eSigner — Formatting & Utilities
platforms/esigner/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts, src/routes/(protected)/files/[id]/+page.svelte
Quote/style normalization (single→double), indentation/whitespace changes, JSON pretty-printing, and a large reflow of a protected files page; no behavioral changes.
File-Manager — Formatting & Stores
platforms/file-manager/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts
Quote/style normalization and minor string-literal adjustments (e.g., Toast, access permission literals). No behavior changes aside from formatting.
Misc: runtime typing loosened
platforms/dreamSync/client/src/components/auth-modal.tsx
Cast loginSchema / registerSchema to any when passed to zodResolver in useForm (typing loosened; runtime validation unchanged).
Docker Compose: env defaults removed & formatting
docker-compose.core.yml
Reflowed/indented compose file; removed several environment default values (e.g., DATABASE_URL, REGISTRY_DATABASE_URL, PUBLIC_REGISTRY_URL) so they now reference variables without fallbacks; otherwise structural formatting changes only.

Sequence Diagram(s)

sequenceDiagram
participant Browser as Browser (Client)
participant Router as Router
participant AuthAPI as Auth API (POST /login)
participant SSE as SSE Server
participant Storage as sessionStorage
Browser->>AuthAPI: POST /login (auto-login)
AuthAPI-->>Browser: 200 + auth token
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
Note right of Browser: SSE-based flow
Browser->>SSE: open EventSource
SSE-->>Browser: onmessage (token OR version_mismatch)
alt token received
Browser->>AuthAPI: signInWithCustomToken(token)
AuthAPI-->>Browser: auth success
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
else version_mismatch
Browser->>Browser: handle version mismatch (show error/notify)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

bug

Suggested reviewers

  • coodos
  • sosweetham

Poem

🐇 I hopped through code and kept the track,
I cached the path so users come back.
SessionStorage held the post-login key,
SSE sang tokens and set them free,
Now users land where they meant to be. 🎉

🚥 Pre-merge checks | ✅ 3 | ❌ 2
❌ Failed checks (1 warning, 1 inconclusive)
Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 18.18% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Out of Scope Changes check❓ InconclusiveThe majority of changes are formatting-only (quotes, indentation) across multiple platforms. The only functional changes are in eVoting login redirection and minor fixes, all directly supporting the PR objective. Docker-compose environment variable changes appear scoped to configuration.Clarify whether the extensive formatting changes across esigner, file-manager platforms and docker-compose.core.yml environment variable defaults are intentional or should be separated into a distinct formatting/chore PR.
✅ Passed checks (3 passed)
Check nameStatusExplanation
Title check✅ PassedThe PR title 'fix: user-redirection-when-vote' clearly indicates a fix to user redirection related to voting, which aligns with the main objective of fixing the redirect issue after login.
Description check✅ PassedThe PR description includes all required template sections: change description, issue number, type of change, testing method, and completed checklist. The description clearly explains the fix for redirection to vote ID instead of home page.
Linked Issues check✅ PassedThe code changes in login pages implement redirect handling logic that preserves and uses the vote ID from URL parameters when logging in, directly addressing issue #703's requirement for post-login redirection to the specific voting page.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Fix all issues with AI agents
In `@infrastructure/eid-wallet/src/routes/`(app)/scan-qr/+page.svelte:
- Around line 95-100: Remove the debug $effect block that logs
selectedBlindVoteOption to the console; locate the reactive $effect referencing
$selectedBlindVoteOption and delete the entire block (or replace it with a
non-logging dev-only guard around the effect if runtime debugging is needed),
ensuring there are no remaining console.log statements related to
selectedBlindVoteOption.
In `@platforms/eVoting/src/app/`(auth)/login/page.tsx:
- Line 189: Update the typo in the login page JSX where the span reads "Click
the button below using you" to "Click the button below using your"; locate the
span in the login page component (page.tsx) and correct the string literal so
wording matches the desktop version.
- Around line 44-47: The redirect check currently accepts values that start with
"/" which still allows protocol-relative URLs like "//evil.com"; update the
validation where redirect is handled (the conditional using
redirect.startsWith("/") and the subsequent setRedirectTo and
sessionStorage.setItem calls) to explicitly reject protocol-relative paths by
ensuring the second character is not "/" (e.g., require redirect.startsWith("/")
&& redirect[1] !== "/") or validate that redirect is a safe local pathname
(parse and confirm it has no host/authority component) before calling
setRedirectTo and sessionStorage.setItem("postLoginRedirect", ...).
- Around line 137-141: The SSE handler uses the redirectTo state but the
useEffect that registers it does not include redirectTo in its dependency array,
risking a stale closure; update the useEffect that sets up the SSE handler (the
effect that reads sessionStorage.getItem("postLoginRedirect") and calls
window.location.href = redirect) to include redirectTo in its dependency array
so the handler always captures the latest redirectTo value, and ensure any
cleanup/registration logic (the SSE subscription) still runs correctly when
redirectTo changes.
🧹 Nitpick comments (2)
platforms/eVoting/src/app/(auth)/login/page.tsx (2)

44-47: Fix inconsistent indentation.

The code block has inconsistent indentation which affects readability. The if block body should be indented consistently with the surrounding code.

🔧 Proposed fix
 if (redirect && redirect.startsWith("/")) {
- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }

95-99: Fix inconsistent indentation in redirect logic.

Similar to the earlier block, this code has inconsistent indentation that should be corrected for readability and maintainability.

🔧 Proposed fix
 const redirect =
- sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";--sessionStorage.removeItem("postLoginRedirect");-window.location.href = redirect;+ sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";+ sessionStorage.removeItem("postLoginRedirect");+ window.location.href = redirect;

Comment threadinfrastructure/eid-wallet/src/routes/(app)/scan-qr/+page.svelte Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
@grv-saini-20
grv-saini-20 marked this pull request as ready for review January 28, 2026 13:20

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
platforms/eVoting/src/app/(auth)/login/page.tsx (1)

24-47: Persist redirect before early return to avoid losing it in auto-login flows.
If the login page is first opened with ename/session/signature (e.g., a new tab on mobile), the redirect param is ignored because the effect returns before saving it. That can fall back to / even when a redirect was provided.

🐛 Proposed fix
- if (ename && session && signature) {- // Clean up URL- window.history.replaceState({}, '', window.location.pathname);-- // Auto-submit login- handleAutoLogin(ename, session, signature, appVersion || '0.4.0');- return;- }-- if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }++ if (ename && session && signature) {+ // Clean up URL+ window.history.replaceState({}, '', window.location.pathname);++ // Auto-submit login+ handleAutoLogin(ename, session, signature, appVersion || '0.4.0');+ return;+ }
🤖 Fix all issues with AI agents
In `@infrastructure/control-panel/src/lib/ui/Table/Table.svelte`:
- Line 377: The snippet parameter for BodyCell is using the bare Record type
causing a TS error; change the parameter type for data in the BodyCell snippet
to be Record<string, TableCell<T>> (matching the component's generic T and the
TableCell type) so the snippet declaration reads BodyCell(data: Record<string,
TableCell<T>>, field: string, i: number) and aligns with the component generics
and usages of TableCell<T>.

Comment threadinfrastructure/control-panel/src/lib/ui/Table/Table.svelte Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/dreamSync/client/src/components/auth-modal.tsx`:
- Around line 41-43: The useForm call for loginForm is using an unnecessary cast
that disables type inference; remove the "as any" cast on zodResolver so
zodResolver(loginSchema) is passed directly to useForm (loginForm) and let the
resolver infer types from loginSchema; update the same pattern where zodResolver
is used for other forms to drop the "as any" casts.

Comment threadplatforms/dreamSync/client/src/components/auth-modal.tsx

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Fix all issues with AI agents
In `@docker-compose.core.yml`:
- Around line 74-96: Replace the hardcoded default values for the registry
service environment variables so the compose file requires values from .env:
remove the default fallbacks from NODE_ENV, DATABASE_URL, REGISTRY_SHARED_SECRET
and PUBLIC_REGISTRY_URL (use ${NODE_ENV}, ${REGISTRY_DATABASE_URL},
${REGISTRY_SHARED_SECRET}, ${PUBLIC_REGISTRY_URL} respectively), and mirror the
same change for the evault-core service; then update .env.example to document
DATABASE_URL and REGISTRY_SHARED_SECRET (and PUBLIC_REGISTRY_URL) as required
secrets/connection strings so Docker Compose fails if they are not provided.
- Around line 36-72: Remove the hard-coded password from the neo4j service: stop
setting NEO4J_AUTH=neo4j/passkipooski in the environment and instead require a
NEO4J_PASSWORD environment variable (provided via a .env file or env_file kept
out of VCS) and set NEO4J_AUTH from that secret outside the repository; then
update the neo4j healthcheck to perform container-side expansion by invoking a
shell (e.g., change the healthcheck test to use "bash -lc" and reference
"$NEO4J_PASSWORD" inside that command so the password is expanded inside the
container when running cypher-shell) — modify the neo4j service environment and
the healthcheck test (referencing the neo4j service, NEO4J_AUTH/NEO4J_PASSWORD,
and the healthcheck test block) accordingly.

Comment threaddocker-compose.core.yml
Comment threaddocker-compose.core.yml
@coodos

Copy link
Copy Markdown
Contributor

approved at the condition you fix code rabbit suggestions

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

well...

Image

@coodoscoodos closed this Jan 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] User is redirected to home page instead of vote after login from chat

2 participants

@grv-saini-20@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: user-redirection-when-vote - #726

Closed
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote
Closed

fix: user-redirection-when-vote#726
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote

Conversation

@grv-saini-20

@grv-saini-20grv-saini-20 commented Jan 27, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fixed the issue of redirection to home page instead of to the vote id after user successfully login to evoting.

Issue Number

closes#703

Type of change

  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)

How the change has been tested

Manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Persist and honor post-login redirects (URL param + session storage) so users return to their intended page after sign-in.
  • Bug Fixes

    • Improved authentication event-stream handling and unified redirect resolution across login flows.
    • Minor mobile login text fix.
  • Chores

    • Broad formatting and quote-style standardization.
    • Small typing/format consistency updates and manifest/config reflow (including env var default adjustments).

✏️ Tip: You can customize this high-level summary in your review settings.

@grv-saini-20grv-saini-20 self-assigned this Jan 27, 2026
@grv-saini-20
grv-saini-20 marked this pull request as draft January 27, 2026 09:07
@coderabbitai

coderabbitaiBot commented Jan 27, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Captures redirect query in eVoting login, persists it as postLoginRedirect in sessionStorage, and resolves/clears it after both POST and SSE login flows; SSE effect now depends on redirectTo. Additionally, widespread formatting/quote-style normalization across multiple platform repos and minor Docker Compose env default removals.

Changes

Cohort / File(s)Summary
eVoting Login Redirect Fix
platforms/eVoting/src/app/(auth)/login/page.tsx
Parse redirect query into redirectTo; persist "postLoginRedirect" in sessionStorage; resolve and clear that key after POST and SSE-based login completions; add redirectTo to SSE effect deps; minor mobile UI text fix.
SSE Event Handling (Blabsy)
platforms/blabsy/src/components/login/login-main.tsx
Refactored watchEventStream callback: explicit onopen, onmessage, onerror handlers; separated version-mismatch and token flows; added signInWithCustomToken to useCallback deps.
Control Panel Table Typing
infrastructure/control-panel/src/lib/ui/Table/Table.svelte
Tightened BodyCell snippet typing to Record<string, TableCell<T>>, propagating generic T.
eSigner — Formatting & Utilities
platforms/esigner/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts, src/routes/(protected)/files/[id]/+page.svelte
Quote/style normalization (single→double), indentation/whitespace changes, JSON pretty-printing, and a large reflow of a protected files page; no behavioral changes.
File-Manager — Formatting & Stores
platforms/file-manager/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts
Quote/style normalization and minor string-literal adjustments (e.g., Toast, access permission literals). No behavior changes aside from formatting.
Misc: runtime typing loosened
platforms/dreamSync/client/src/components/auth-modal.tsx
Cast loginSchema / registerSchema to any when passed to zodResolver in useForm (typing loosened; runtime validation unchanged).
Docker Compose: env defaults removed & formatting
docker-compose.core.yml
Reflowed/indented compose file; removed several environment default values (e.g., DATABASE_URL, REGISTRY_DATABASE_URL, PUBLIC_REGISTRY_URL) so they now reference variables without fallbacks; otherwise structural formatting changes only.

Sequence Diagram(s)

sequenceDiagram
participant Browser as Browser (Client)
participant Router as Router
participant AuthAPI as Auth API (POST /login)
participant SSE as SSE Server
participant Storage as sessionStorage
Browser->>AuthAPI: POST /login (auto-login)
AuthAPI-->>Browser: 200 + auth token
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
Note right of Browser: SSE-based flow
Browser->>SSE: open EventSource
SSE-->>Browser: onmessage (token OR version_mismatch)
alt token received
Browser->>AuthAPI: signInWithCustomToken(token)
AuthAPI-->>Browser: auth success
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
else version_mismatch
Browser->>Browser: handle version mismatch (show error/notify)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

bug

Suggested reviewers

  • coodos
  • sosweetham

Poem

🐇 I hopped through code and kept the track,
I cached the path so users come back.
SessionStorage held the post-login key,
SSE sang tokens and set them free,
Now users land where they meant to be. 🎉

🚥 Pre-merge checks | ✅ 3 | ❌ 2
❌ Failed checks (1 warning, 1 inconclusive)
Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 18.18% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Out of Scope Changes check❓ InconclusiveThe majority of changes are formatting-only (quotes, indentation) across multiple platforms. The only functional changes are in eVoting login redirection and minor fixes, all directly supporting the PR objective. Docker-compose environment variable changes appear scoped to configuration.Clarify whether the extensive formatting changes across esigner, file-manager platforms and docker-compose.core.yml environment variable defaults are intentional or should be separated into a distinct formatting/chore PR.
✅ Passed checks (3 passed)
Check nameStatusExplanation
Title check✅ PassedThe PR title 'fix: user-redirection-when-vote' clearly indicates a fix to user redirection related to voting, which aligns with the main objective of fixing the redirect issue after login.
Description check✅ PassedThe PR description includes all required template sections: change description, issue number, type of change, testing method, and completed checklist. The description clearly explains the fix for redirection to vote ID instead of home page.
Linked Issues check✅ PassedThe code changes in login pages implement redirect handling logic that preserves and uses the vote ID from URL parameters when logging in, directly addressing issue #703's requirement for post-login redirection to the specific voting page.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Fix all issues with AI agents
In `@infrastructure/eid-wallet/src/routes/`(app)/scan-qr/+page.svelte:
- Around line 95-100: Remove the debug $effect block that logs
selectedBlindVoteOption to the console; locate the reactive $effect referencing
$selectedBlindVoteOption and delete the entire block (or replace it with a
non-logging dev-only guard around the effect if runtime debugging is needed),
ensuring there are no remaining console.log statements related to
selectedBlindVoteOption.
In `@platforms/eVoting/src/app/`(auth)/login/page.tsx:
- Line 189: Update the typo in the login page JSX where the span reads "Click
the button below using you" to "Click the button below using your"; locate the
span in the login page component (page.tsx) and correct the string literal so
wording matches the desktop version.
- Around line 44-47: The redirect check currently accepts values that start with
"/" which still allows protocol-relative URLs like "//evil.com"; update the
validation where redirect is handled (the conditional using
redirect.startsWith("/") and the subsequent setRedirectTo and
sessionStorage.setItem calls) to explicitly reject protocol-relative paths by
ensuring the second character is not "/" (e.g., require redirect.startsWith("/")
&& redirect[1] !== "/") or validate that redirect is a safe local pathname
(parse and confirm it has no host/authority component) before calling
setRedirectTo and sessionStorage.setItem("postLoginRedirect", ...).
- Around line 137-141: The SSE handler uses the redirectTo state but the
useEffect that registers it does not include redirectTo in its dependency array,
risking a stale closure; update the useEffect that sets up the SSE handler (the
effect that reads sessionStorage.getItem("postLoginRedirect") and calls
window.location.href = redirect) to include redirectTo in its dependency array
so the handler always captures the latest redirectTo value, and ensure any
cleanup/registration logic (the SSE subscription) still runs correctly when
redirectTo changes.
🧹 Nitpick comments (2)
platforms/eVoting/src/app/(auth)/login/page.tsx (2)

44-47: Fix inconsistent indentation.

The code block has inconsistent indentation which affects readability. The if block body should be indented consistently with the surrounding code.

🔧 Proposed fix
 if (redirect && redirect.startsWith("/")) {
- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }

95-99: Fix inconsistent indentation in redirect logic.

Similar to the earlier block, this code has inconsistent indentation that should be corrected for readability and maintainability.

🔧 Proposed fix
 const redirect =
- sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";--sessionStorage.removeItem("postLoginRedirect");-window.location.href = redirect;+ sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";+ sessionStorage.removeItem("postLoginRedirect");+ window.location.href = redirect;

Comment threadinfrastructure/eid-wallet/src/routes/(app)/scan-qr/+page.svelte Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
@grv-saini-20
grv-saini-20 marked this pull request as ready for review January 28, 2026 13:20

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
platforms/eVoting/src/app/(auth)/login/page.tsx (1)

24-47: Persist redirect before early return to avoid losing it in auto-login flows.
If the login page is first opened with ename/session/signature (e.g., a new tab on mobile), the redirect param is ignored because the effect returns before saving it. That can fall back to / even when a redirect was provided.

🐛 Proposed fix
- if (ename && session && signature) {- // Clean up URL- window.history.replaceState({}, '', window.location.pathname);-- // Auto-submit login- handleAutoLogin(ename, session, signature, appVersion || '0.4.0');- return;- }-- if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }++ if (ename && session && signature) {+ // Clean up URL+ window.history.replaceState({}, '', window.location.pathname);++ // Auto-submit login+ handleAutoLogin(ename, session, signature, appVersion || '0.4.0');+ return;+ }
🤖 Fix all issues with AI agents
In `@infrastructure/control-panel/src/lib/ui/Table/Table.svelte`:
- Line 377: The snippet parameter for BodyCell is using the bare Record type
causing a TS error; change the parameter type for data in the BodyCell snippet
to be Record<string, TableCell<T>> (matching the component's generic T and the
TableCell type) so the snippet declaration reads BodyCell(data: Record<string,
TableCell<T>>, field: string, i: number) and aligns with the component generics
and usages of TableCell<T>.

Comment threadinfrastructure/control-panel/src/lib/ui/Table/Table.svelte Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/dreamSync/client/src/components/auth-modal.tsx`:
- Around line 41-43: The useForm call for loginForm is using an unnecessary cast
that disables type inference; remove the "as any" cast on zodResolver so
zodResolver(loginSchema) is passed directly to useForm (loginForm) and let the
resolver infer types from loginSchema; update the same pattern where zodResolver
is used for other forms to drop the "as any" casts.

Comment threadplatforms/dreamSync/client/src/components/auth-modal.tsx

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Fix all issues with AI agents
In `@docker-compose.core.yml`:
- Around line 74-96: Replace the hardcoded default values for the registry
service environment variables so the compose file requires values from .env:
remove the default fallbacks from NODE_ENV, DATABASE_URL, REGISTRY_SHARED_SECRET
and PUBLIC_REGISTRY_URL (use ${NODE_ENV}, ${REGISTRY_DATABASE_URL},
${REGISTRY_SHARED_SECRET}, ${PUBLIC_REGISTRY_URL} respectively), and mirror the
same change for the evault-core service; then update .env.example to document
DATABASE_URL and REGISTRY_SHARED_SECRET (and PUBLIC_REGISTRY_URL) as required
secrets/connection strings so Docker Compose fails if they are not provided.
- Around line 36-72: Remove the hard-coded password from the neo4j service: stop
setting NEO4J_AUTH=neo4j/passkipooski in the environment and instead require a
NEO4J_PASSWORD environment variable (provided via a .env file or env_file kept
out of VCS) and set NEO4J_AUTH from that secret outside the repository; then
update the neo4j healthcheck to perform container-side expansion by invoking a
shell (e.g., change the healthcheck test to use "bash -lc" and reference
"$NEO4J_PASSWORD" inside that command so the password is expanded inside the
container when running cypher-shell) — modify the neo4j service environment and
the healthcheck test (referencing the neo4j service, NEO4J_AUTH/NEO4J_PASSWORD,
and the healthcheck test block) accordingly.

Comment threaddocker-compose.core.yml
Comment threaddocker-compose.core.yml
@coodos

Copy link
Copy Markdown
Contributor

approved at the condition you fix code rabbit suggestions

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

well...

Image

@coodoscoodos closed this Jan 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] User is redirected to home page instead of vote after login from chat

2 participants

@grv-saini-20@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: user-redirection-when-vote - #726

Closed
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote
Closed

fix: user-redirection-when-vote#726
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote

Conversation

@grv-saini-20

@grv-saini-20grv-saini-20 commented Jan 27, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fixed the issue of redirection to home page instead of to the vote id after user successfully login to evoting.

Issue Number

closes#703

Type of change

  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)

How the change has been tested

Manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Persist and honor post-login redirects (URL param + session storage) so users return to their intended page after sign-in.
  • Bug Fixes

    • Improved authentication event-stream handling and unified redirect resolution across login flows.
    • Minor mobile login text fix.
  • Chores

    • Broad formatting and quote-style standardization.
    • Small typing/format consistency updates and manifest/config reflow (including env var default adjustments).

✏️ Tip: You can customize this high-level summary in your review settings.

@grv-saini-20grv-saini-20 self-assigned this Jan 27, 2026
@grv-saini-20
grv-saini-20 marked this pull request as draft January 27, 2026 09:07
@coderabbitai

coderabbitaiBot commented Jan 27, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Captures redirect query in eVoting login, persists it as postLoginRedirect in sessionStorage, and resolves/clears it after both POST and SSE login flows; SSE effect now depends on redirectTo. Additionally, widespread formatting/quote-style normalization across multiple platform repos and minor Docker Compose env default removals.

Changes

Cohort / File(s)Summary
eVoting Login Redirect Fix
platforms/eVoting/src/app/(auth)/login/page.tsx
Parse redirect query into redirectTo; persist "postLoginRedirect" in sessionStorage; resolve and clear that key after POST and SSE-based login completions; add redirectTo to SSE effect deps; minor mobile UI text fix.
SSE Event Handling (Blabsy)
platforms/blabsy/src/components/login/login-main.tsx
Refactored watchEventStream callback: explicit onopen, onmessage, onerror handlers; separated version-mismatch and token flows; added signInWithCustomToken to useCallback deps.
Control Panel Table Typing
infrastructure/control-panel/src/lib/ui/Table/Table.svelte
Tightened BodyCell snippet typing to Record<string, TableCell<T>>, propagating generic T.
eSigner — Formatting & Utilities
platforms/esigner/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts, src/routes/(protected)/files/[id]/+page.svelte
Quote/style normalization (single→double), indentation/whitespace changes, JSON pretty-printing, and a large reflow of a protected files page; no behavioral changes.
File-Manager — Formatting & Stores
platforms/file-manager/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts
Quote/style normalization and minor string-literal adjustments (e.g., Toast, access permission literals). No behavior changes aside from formatting.
Misc: runtime typing loosened
platforms/dreamSync/client/src/components/auth-modal.tsx
Cast loginSchema / registerSchema to any when passed to zodResolver in useForm (typing loosened; runtime validation unchanged).
Docker Compose: env defaults removed & formatting
docker-compose.core.yml
Reflowed/indented compose file; removed several environment default values (e.g., DATABASE_URL, REGISTRY_DATABASE_URL, PUBLIC_REGISTRY_URL) so they now reference variables without fallbacks; otherwise structural formatting changes only.

Sequence Diagram(s)

sequenceDiagram
participant Browser as Browser (Client)
participant Router as Router
participant AuthAPI as Auth API (POST /login)
participant SSE as SSE Server
participant Storage as sessionStorage
Browser->>AuthAPI: POST /login (auto-login)
AuthAPI-->>Browser: 200 + auth token
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
Note right of Browser: SSE-based flow
Browser->>SSE: open EventSource
SSE-->>Browser: onmessage (token OR version_mismatch)
alt token received
Browser->>AuthAPI: signInWithCustomToken(token)
AuthAPI-->>Browser: auth success
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
else version_mismatch
Browser->>Browser: handle version mismatch (show error/notify)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

bug

Suggested reviewers

  • coodos
  • sosweetham

Poem

🐇 I hopped through code and kept the track,
I cached the path so users come back.
SessionStorage held the post-login key,
SSE sang tokens and set them free,
Now users land where they meant to be. 🎉

🚥 Pre-merge checks | ✅ 3 | ❌ 2
❌ Failed checks (1 warning, 1 inconclusive)
Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 18.18% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Out of Scope Changes check❓ InconclusiveThe majority of changes are formatting-only (quotes, indentation) across multiple platforms. The only functional changes are in eVoting login redirection and minor fixes, all directly supporting the PR objective. Docker-compose environment variable changes appear scoped to configuration.Clarify whether the extensive formatting changes across esigner, file-manager platforms and docker-compose.core.yml environment variable defaults are intentional or should be separated into a distinct formatting/chore PR.
✅ Passed checks (3 passed)
Check nameStatusExplanation
Title check✅ PassedThe PR title 'fix: user-redirection-when-vote' clearly indicates a fix to user redirection related to voting, which aligns with the main objective of fixing the redirect issue after login.
Description check✅ PassedThe PR description includes all required template sections: change description, issue number, type of change, testing method, and completed checklist. The description clearly explains the fix for redirection to vote ID instead of home page.
Linked Issues check✅ PassedThe code changes in login pages implement redirect handling logic that preserves and uses the vote ID from URL parameters when logging in, directly addressing issue #703's requirement for post-login redirection to the specific voting page.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Fix all issues with AI agents
In `@infrastructure/eid-wallet/src/routes/`(app)/scan-qr/+page.svelte:
- Around line 95-100: Remove the debug $effect block that logs
selectedBlindVoteOption to the console; locate the reactive $effect referencing
$selectedBlindVoteOption and delete the entire block (or replace it with a
non-logging dev-only guard around the effect if runtime debugging is needed),
ensuring there are no remaining console.log statements related to
selectedBlindVoteOption.
In `@platforms/eVoting/src/app/`(auth)/login/page.tsx:
- Line 189: Update the typo in the login page JSX where the span reads "Click
the button below using you" to "Click the button below using your"; locate the
span in the login page component (page.tsx) and correct the string literal so
wording matches the desktop version.
- Around line 44-47: The redirect check currently accepts values that start with
"/" which still allows protocol-relative URLs like "//evil.com"; update the
validation where redirect is handled (the conditional using
redirect.startsWith("/") and the subsequent setRedirectTo and
sessionStorage.setItem calls) to explicitly reject protocol-relative paths by
ensuring the second character is not "/" (e.g., require redirect.startsWith("/")
&& redirect[1] !== "/") or validate that redirect is a safe local pathname
(parse and confirm it has no host/authority component) before calling
setRedirectTo and sessionStorage.setItem("postLoginRedirect", ...).
- Around line 137-141: The SSE handler uses the redirectTo state but the
useEffect that registers it does not include redirectTo in its dependency array,
risking a stale closure; update the useEffect that sets up the SSE handler (the
effect that reads sessionStorage.getItem("postLoginRedirect") and calls
window.location.href = redirect) to include redirectTo in its dependency array
so the handler always captures the latest redirectTo value, and ensure any
cleanup/registration logic (the SSE subscription) still runs correctly when
redirectTo changes.
🧹 Nitpick comments (2)
platforms/eVoting/src/app/(auth)/login/page.tsx (2)

44-47: Fix inconsistent indentation.

The code block has inconsistent indentation which affects readability. The if block body should be indented consistently with the surrounding code.

🔧 Proposed fix
 if (redirect && redirect.startsWith("/")) {
- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }

95-99: Fix inconsistent indentation in redirect logic.

Similar to the earlier block, this code has inconsistent indentation that should be corrected for readability and maintainability.

🔧 Proposed fix
 const redirect =
- sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";--sessionStorage.removeItem("postLoginRedirect");-window.location.href = redirect;+ sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";+ sessionStorage.removeItem("postLoginRedirect");+ window.location.href = redirect;

Comment threadinfrastructure/eid-wallet/src/routes/(app)/scan-qr/+page.svelte Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
@grv-saini-20
grv-saini-20 marked this pull request as ready for review January 28, 2026 13:20

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
platforms/eVoting/src/app/(auth)/login/page.tsx (1)

24-47: Persist redirect before early return to avoid losing it in auto-login flows.
If the login page is first opened with ename/session/signature (e.g., a new tab on mobile), the redirect param is ignored because the effect returns before saving it. That can fall back to / even when a redirect was provided.

🐛 Proposed fix
- if (ename && session && signature) {- // Clean up URL- window.history.replaceState({}, '', window.location.pathname);-- // Auto-submit login- handleAutoLogin(ename, session, signature, appVersion || '0.4.0');- return;- }-- if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }++ if (ename && session && signature) {+ // Clean up URL+ window.history.replaceState({}, '', window.location.pathname);++ // Auto-submit login+ handleAutoLogin(ename, session, signature, appVersion || '0.4.0');+ return;+ }
🤖 Fix all issues with AI agents
In `@infrastructure/control-panel/src/lib/ui/Table/Table.svelte`:
- Line 377: The snippet parameter for BodyCell is using the bare Record type
causing a TS error; change the parameter type for data in the BodyCell snippet
to be Record<string, TableCell<T>> (matching the component's generic T and the
TableCell type) so the snippet declaration reads BodyCell(data: Record<string,
TableCell<T>>, field: string, i: number) and aligns with the component generics
and usages of TableCell<T>.

Comment threadinfrastructure/control-panel/src/lib/ui/Table/Table.svelte Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/dreamSync/client/src/components/auth-modal.tsx`:
- Around line 41-43: The useForm call for loginForm is using an unnecessary cast
that disables type inference; remove the "as any" cast on zodResolver so
zodResolver(loginSchema) is passed directly to useForm (loginForm) and let the
resolver infer types from loginSchema; update the same pattern where zodResolver
is used for other forms to drop the "as any" casts.

Comment threadplatforms/dreamSync/client/src/components/auth-modal.tsx

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Fix all issues with AI agents
In `@docker-compose.core.yml`:
- Around line 74-96: Replace the hardcoded default values for the registry
service environment variables so the compose file requires values from .env:
remove the default fallbacks from NODE_ENV, DATABASE_URL, REGISTRY_SHARED_SECRET
and PUBLIC_REGISTRY_URL (use ${NODE_ENV}, ${REGISTRY_DATABASE_URL},
${REGISTRY_SHARED_SECRET}, ${PUBLIC_REGISTRY_URL} respectively), and mirror the
same change for the evault-core service; then update .env.example to document
DATABASE_URL and REGISTRY_SHARED_SECRET (and PUBLIC_REGISTRY_URL) as required
secrets/connection strings so Docker Compose fails if they are not provided.
- Around line 36-72: Remove the hard-coded password from the neo4j service: stop
setting NEO4J_AUTH=neo4j/passkipooski in the environment and instead require a
NEO4J_PASSWORD environment variable (provided via a .env file or env_file kept
out of VCS) and set NEO4J_AUTH from that secret outside the repository; then
update the neo4j healthcheck to perform container-side expansion by invoking a
shell (e.g., change the healthcheck test to use "bash -lc" and reference
"$NEO4J_PASSWORD" inside that command so the password is expanded inside the
container when running cypher-shell) — modify the neo4j service environment and
the healthcheck test (referencing the neo4j service, NEO4J_AUTH/NEO4J_PASSWORD,
and the healthcheck test block) accordingly.

Comment threaddocker-compose.core.yml
Comment threaddocker-compose.core.yml
@coodos

Copy link
Copy Markdown
Contributor

approved at the condition you fix code rabbit suggestions

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

well...

Image

@coodoscoodos closed this Jan 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] User is redirected to home page instead of vote after login from chat

2 participants

@grv-saini-20@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: user-redirection-when-vote - #726

Closed
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote
Closed

fix: user-redirection-when-vote#726
grv-saini-20 wants to merge 12 commits into
mainfrom
fix/user-redirection-when-vote

Conversation

@grv-saini-20

@grv-saini-20grv-saini-20 commented Jan 27, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fixed the issue of redirection to home page instead of to the vote id after user successfully login to evoting.

Issue Number

closes#703

Type of change

  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)

How the change has been tested

Manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Persist and honor post-login redirects (URL param + session storage) so users return to their intended page after sign-in.
  • Bug Fixes

    • Improved authentication event-stream handling and unified redirect resolution across login flows.
    • Minor mobile login text fix.
  • Chores

    • Broad formatting and quote-style standardization.
    • Small typing/format consistency updates and manifest/config reflow (including env var default adjustments).

✏️ Tip: You can customize this high-level summary in your review settings.

@grv-saini-20grv-saini-20 self-assigned this Jan 27, 2026
@grv-saini-20
grv-saini-20 marked this pull request as draft January 27, 2026 09:07
@coderabbitai

coderabbitaiBot commented Jan 27, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Captures redirect query in eVoting login, persists it as postLoginRedirect in sessionStorage, and resolves/clears it after both POST and SSE login flows; SSE effect now depends on redirectTo. Additionally, widespread formatting/quote-style normalization across multiple platform repos and minor Docker Compose env default removals.

Changes

Cohort / File(s)Summary
eVoting Login Redirect Fix
platforms/eVoting/src/app/(auth)/login/page.tsx
Parse redirect query into redirectTo; persist "postLoginRedirect" in sessionStorage; resolve and clear that key after POST and SSE-based login completions; add redirectTo to SSE effect deps; minor mobile UI text fix.
SSE Event Handling (Blabsy)
platforms/blabsy/src/components/login/login-main.tsx
Refactored watchEventStream callback: explicit onopen, onmessage, onerror handlers; separated version-mismatch and token flows; added signInWithCustomToken to useCallback deps.
Control Panel Table Typing
infrastructure/control-panel/src/lib/ui/Table/Table.svelte
Tightened BodyCell snippet typing to Record<string, TableCell<T>>, propagating generic T.
eSigner — Formatting & Utilities
platforms/esigner/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts, src/routes/(protected)/files/[id]/+page.svelte
Quote/style normalization (single→double), indentation/whitespace changes, JSON pretty-printing, and a large reflow of a protected files page; no behavioral changes.
File-Manager — Formatting & Stores
platforms/file-manager/...
package.json, src/app.css, src/app.d.ts, src/app.html, src/lib/stores/*, src/lib/utils/*, static/site.webmanifest, svelte.config.js, tsconfig.json, vite.config.ts
Quote/style normalization and minor string-literal adjustments (e.g., Toast, access permission literals). No behavior changes aside from formatting.
Misc: runtime typing loosened
platforms/dreamSync/client/src/components/auth-modal.tsx
Cast loginSchema / registerSchema to any when passed to zodResolver in useForm (typing loosened; runtime validation unchanged).
Docker Compose: env defaults removed & formatting
docker-compose.core.yml
Reflowed/indented compose file; removed several environment default values (e.g., DATABASE_URL, REGISTRY_DATABASE_URL, PUBLIC_REGISTRY_URL) so they now reference variables without fallbacks; otherwise structural formatting changes only.

Sequence Diagram(s)

sequenceDiagram
participant Browser as Browser (Client)
participant Router as Router
participant AuthAPI as Auth API (POST /login)
participant SSE as SSE Server
participant Storage as sessionStorage
Browser->>AuthAPI: POST /login (auto-login)
AuthAPI-->>Browser: 200 + auth token
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
Note right of Browser: SSE-based flow
Browser->>SSE: open EventSource
SSE-->>Browser: onmessage (token OR version_mismatch)
alt token received
Browser->>AuthAPI: signInWithCustomToken(token)
AuthAPI-->>Browser: auth success
Browser->>Storage: read "postLoginRedirect" or use redirectTo or "/"
Browser->>Storage: remove "postLoginRedirect"
Browser->>Router: navigate to resolved redirect
else version_mismatch
Browser->>Browser: handle version mismatch (show error/notify)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

bug

Suggested reviewers

  • coodos
  • sosweetham

Poem

🐇 I hopped through code and kept the track,
I cached the path so users come back.
SessionStorage held the post-login key,
SSE sang tokens and set them free,
Now users land where they meant to be. 🎉

🚥 Pre-merge checks | ✅ 3 | ❌ 2
❌ Failed checks (1 warning, 1 inconclusive)
Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 18.18% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Out of Scope Changes check❓ InconclusiveThe majority of changes are formatting-only (quotes, indentation) across multiple platforms. The only functional changes are in eVoting login redirection and minor fixes, all directly supporting the PR objective. Docker-compose environment variable changes appear scoped to configuration.Clarify whether the extensive formatting changes across esigner, file-manager platforms and docker-compose.core.yml environment variable defaults are intentional or should be separated into a distinct formatting/chore PR.
✅ Passed checks (3 passed)
Check nameStatusExplanation
Title check✅ PassedThe PR title 'fix: user-redirection-when-vote' clearly indicates a fix to user redirection related to voting, which aligns with the main objective of fixing the redirect issue after login.
Description check✅ PassedThe PR description includes all required template sections: change description, issue number, type of change, testing method, and completed checklist. The description clearly explains the fix for redirection to vote ID instead of home page.
Linked Issues check✅ PassedThe code changes in login pages implement redirect handling logic that preserves and uses the vote ID from URL parameters when logging in, directly addressing issue #703's requirement for post-login redirection to the specific voting page.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Fix all issues with AI agents
In `@infrastructure/eid-wallet/src/routes/`(app)/scan-qr/+page.svelte:
- Around line 95-100: Remove the debug $effect block that logs
selectedBlindVoteOption to the console; locate the reactive $effect referencing
$selectedBlindVoteOption and delete the entire block (or replace it with a
non-logging dev-only guard around the effect if runtime debugging is needed),
ensuring there are no remaining console.log statements related to
selectedBlindVoteOption.
In `@platforms/eVoting/src/app/`(auth)/login/page.tsx:
- Line 189: Update the typo in the login page JSX where the span reads "Click
the button below using you" to "Click the button below using your"; locate the
span in the login page component (page.tsx) and correct the string literal so
wording matches the desktop version.
- Around line 44-47: The redirect check currently accepts values that start with
"/" which still allows protocol-relative URLs like "//evil.com"; update the
validation where redirect is handled (the conditional using
redirect.startsWith("/") and the subsequent setRedirectTo and
sessionStorage.setItem calls) to explicitly reject protocol-relative paths by
ensuring the second character is not "/" (e.g., require redirect.startsWith("/")
&& redirect[1] !== "/") or validate that redirect is a safe local pathname
(parse and confirm it has no host/authority component) before calling
setRedirectTo and sessionStorage.setItem("postLoginRedirect", ...).
- Around line 137-141: The SSE handler uses the redirectTo state but the
useEffect that registers it does not include redirectTo in its dependency array,
risking a stale closure; update the useEffect that sets up the SSE handler (the
effect that reads sessionStorage.getItem("postLoginRedirect") and calls
window.location.href = redirect) to include redirectTo in its dependency array
so the handler always captures the latest redirectTo value, and ensure any
cleanup/registration logic (the SSE subscription) still runs correctly when
redirectTo changes.
🧹 Nitpick comments (2)
platforms/eVoting/src/app/(auth)/login/page.tsx (2)

44-47: Fix inconsistent indentation.

The code block has inconsistent indentation which affects readability. The if block body should be indented consistently with the surrounding code.

🔧 Proposed fix
 if (redirect && redirect.startsWith("/")) {
- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }

95-99: Fix inconsistent indentation in redirect logic.

Similar to the earlier block, this code has inconsistent indentation that should be corrected for readability and maintainability.

🔧 Proposed fix
 const redirect =
- sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";--sessionStorage.removeItem("postLoginRedirect");-window.location.href = redirect;+ sessionStorage.getItem("postLoginRedirect") || redirectTo || "/";+ sessionStorage.removeItem("postLoginRedirect");+ window.location.href = redirect;

Comment threadinfrastructure/eid-wallet/src/routes/(app)/scan-qr/+page.svelte Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx Outdated
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
Comment threadplatforms/eVoting/src/app/(auth)/login/page.tsx
@grv-saini-20
grv-saini-20 marked this pull request as ready for review January 28, 2026 13:20

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
platforms/eVoting/src/app/(auth)/login/page.tsx (1)

24-47: Persist redirect before early return to avoid losing it in auto-login flows.
If the login page is first opened with ename/session/signature (e.g., a new tab on mobile), the redirect param is ignored because the effect returns before saving it. That can fall back to / even when a redirect was provided.

🐛 Proposed fix
- if (ename && session && signature) {- // Clean up URL- window.history.replaceState({}, '', window.location.pathname);-- // Auto-submit login- handleAutoLogin(ename, session, signature, appVersion || '0.4.0');- return;- }-- if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {- setRedirectTo(redirect);- sessionStorage.setItem("postLoginRedirect", redirect);- }+ if (redirect && redirect.startsWith("/") && !redirect.startsWith("//")) {+ setRedirectTo(redirect);+ sessionStorage.setItem("postLoginRedirect", redirect);+ }++ if (ename && session && signature) {+ // Clean up URL+ window.history.replaceState({}, '', window.location.pathname);++ // Auto-submit login+ handleAutoLogin(ename, session, signature, appVersion || '0.4.0');+ return;+ }
🤖 Fix all issues with AI agents
In `@infrastructure/control-panel/src/lib/ui/Table/Table.svelte`:
- Line 377: The snippet parameter for BodyCell is using the bare Record type
causing a TS error; change the parameter type for data in the BodyCell snippet
to be Record<string, TableCell<T>> (matching the component's generic T and the
TableCell type) so the snippet declaration reads BodyCell(data: Record<string,
TableCell<T>>, field: string, i: number) and aligns with the component generics
and usages of TableCell<T>.

Comment threadinfrastructure/control-panel/src/lib/ui/Table/Table.svelte Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/dreamSync/client/src/components/auth-modal.tsx`:
- Around line 41-43: The useForm call for loginForm is using an unnecessary cast
that disables type inference; remove the "as any" cast on zodResolver so
zodResolver(loginSchema) is passed directly to useForm (loginForm) and let the
resolver infer types from loginSchema; update the same pattern where zodResolver
is used for other forms to drop the "as any" casts.

Comment threadplatforms/dreamSync/client/src/components/auth-modal.tsx

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Fix all issues with AI agents
In `@docker-compose.core.yml`:
- Around line 74-96: Replace the hardcoded default values for the registry
service environment variables so the compose file requires values from .env:
remove the default fallbacks from NODE_ENV, DATABASE_URL, REGISTRY_SHARED_SECRET
and PUBLIC_REGISTRY_URL (use ${NODE_ENV}, ${REGISTRY_DATABASE_URL},
${REGISTRY_SHARED_SECRET}, ${PUBLIC_REGISTRY_URL} respectively), and mirror the
same change for the evault-core service; then update .env.example to document
DATABASE_URL and REGISTRY_SHARED_SECRET (and PUBLIC_REGISTRY_URL) as required
secrets/connection strings so Docker Compose fails if they are not provided.
- Around line 36-72: Remove the hard-coded password from the neo4j service: stop
setting NEO4J_AUTH=neo4j/passkipooski in the environment and instead require a
NEO4J_PASSWORD environment variable (provided via a .env file or env_file kept
out of VCS) and set NEO4J_AUTH from that secret outside the repository; then
update the neo4j healthcheck to perform container-side expansion by invoking a
shell (e.g., change the healthcheck test to use "bash -lc" and reference
"$NEO4J_PASSWORD" inside that command so the password is expanded inside the
container when running cypher-shell) — modify the neo4j service environment and
the healthcheck test (referencing the neo4j service, NEO4J_AUTH/NEO4J_PASSWORD,
and the healthcheck test block) accordingly.

Comment threaddocker-compose.core.yml
Comment threaddocker-compose.core.yml
@coodos

Copy link
Copy Markdown
Contributor

approved at the condition you fix code rabbit suggestions

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

well...

Image

@coodoscoodos closed this Jan 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] User is redirected to home page instead of vote after login from chat

2 participants

@grv-saini-20@coodos