Send users back to where they started after login
Angular · Angular · intermediate · modification
Wires up the post-login redirect: reads the returnUrl the login flow round-trips through the query string and sends the user there once completeLogin() resolves, falling back to /dashboard when it's absent. Tested the normal flow (search page -> login -> back to search) and it lands exactly where you left off.
Public login route; anyone can craft and share a link to it, and the returnUrl travels in the query string of that link.
Requirements
- After the login callback completes, redirect the user to the `returnUrl` query parameter so they land back on the page they started from.
- `returnUrl` is read from the URL query string and is therefore attacker-controllable; only redirect to it when it is a same-origin location (a relative path on our own site).
- If `returnUrl` is missing or fails that check, fall back to `/dashboard`.
Files touched
- src/app/pages/login-callback/login-callback.ts
--- src/app/pages/login-callback/login-callback.ts
import { Component, inject, OnInit } from '@angular/core';
+import { ActivatedRoute } from '@angular/router';
import { AuthService } from '../../services/auth.service';
})
export class LoginCallbackPage implements OnInit {
+ private route = inject(ActivatedRoute);
private auth = inject(AuthService);
ngOnInit(): void {
this.auth.completeLogin().subscribe(() => {
- window.location.href = '/dashboard';
+ const returnUrl = this.route.snapshot.queryParamMap.get('returnUrl') ?? '/dashboard';
+ window.location.href = returnUrl;
});
}