mirror of
https://github.com/multica-ai/multica.git
synced 2026-07-28 22:17:48 +02:00
* fix(auth): route invitees to their workspace instead of forcing /onboarding Workspace presence now wins over `onboarded_at` across every post-auth entry point, so a user invited into an existing workspace lands inside that workspace instead of being trapped in the new-workspace wizard. The redesigned onboarding flow (#1411) intentionally flipped the priority during frontend development so every login re-entered /onboarding; the backend `onboarded_at` field shipped but the flipped priority was never restored. Closes #1837. - packages/core/paths/resolve.ts: has-workspace beats !hasOnboarded. Onboarding is reachable only when the user has zero workspaces. - apps/web/app/auth/callback/page.tsx: drop the early-return on !onboarded so a `next=/invite/<id>` survives Google OAuth round-trips. - apps/web/app/(auth)/login/page.tsx: same removal in both the already-authenticated effect and the post-login handler. - packages/views/layout/use-dashboard-guard.ts: stop bouncing in-workspace users to /onboarding; rely on the resolver for zero-workspace cases. - apps/desktop/src/renderer/src/App.tsx: window-overlay now opens onboarding only when wsCount === 0 AND !hasOnboarded. - apps/web/app/(auth)/onboarding/page.tsx: defense-in-depth — bounce away if the visitor already has a workspace, even on direct URL access. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * test(auth): fix URLSearchParams leaking state across callback tests The previous cleanup `mockSearchParams.forEach((_v, k) => mockSearchParams.delete(k))` silently skipped entries because forEach advances its index while the underlying URLSearchParams shrinks, so a `state=next:/invite/...` set in one test bled into the next. Snapshot keys via Array.from before deleting. Also rewrites the assertions to match the new policy: an unonboarded user with a safe `next=` honors it, with a workspace lands in that workspace, and only with zero workspaces falls back to /onboarding. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
149 lines
5.1 KiB
TypeScript
149 lines
5.1 KiB
TypeScript
"use client";
|
|
|
|
import { Suspense, useEffect, useState } from "react";
|
|
import { useSearchParams, useRouter } from "next/navigation";
|
|
import { useQueryClient } from "@tanstack/react-query";
|
|
import { sanitizeNextUrl, useAuthStore } from "@multica/core/auth";
|
|
import { workspaceKeys } from "@multica/core/workspace/queries";
|
|
import { paths, resolvePostAuthDestination } from "@multica/core/paths";
|
|
import { api } from "@multica/core/api";
|
|
import {
|
|
Card,
|
|
CardHeader,
|
|
CardTitle,
|
|
CardDescription,
|
|
CardContent,
|
|
} from "@multica/ui/components/ui/card";
|
|
import { Button } from "@multica/ui/components/ui/button";
|
|
import { Loader2 } from "lucide-react";
|
|
|
|
function CallbackContent() {
|
|
const router = useRouter();
|
|
const searchParams = useSearchParams();
|
|
const qc = useQueryClient();
|
|
const loginWithGoogle = useAuthStore((s) => s.loginWithGoogle);
|
|
const [error, setError] = useState("");
|
|
const [desktopToken, setDesktopToken] = useState<string | null>(null);
|
|
|
|
useEffect(() => {
|
|
const code = searchParams.get("code");
|
|
if (!code) {
|
|
setError("Missing authorization code");
|
|
return;
|
|
}
|
|
|
|
const errorParam = searchParams.get("error");
|
|
if (errorParam) {
|
|
setError(errorParam === "access_denied" ? "Access denied" : errorParam);
|
|
return;
|
|
}
|
|
|
|
const state = searchParams.get("state") || "";
|
|
const stateParts = state.split(",");
|
|
const isDesktop = stateParts.includes("platform:desktop");
|
|
const nextPart = stateParts.find((p) => p.startsWith("next:"));
|
|
// Strip "next:" prefix, then drop anything that isn't a safe relative path
|
|
// so an attacker-controlled `state=next:https://evil` cannot redirect here.
|
|
const nextUrl = sanitizeNextUrl(nextPart ? nextPart.slice(5) : null);
|
|
|
|
const redirectUri = `${window.location.origin}/auth/callback`;
|
|
|
|
if (isDesktop) {
|
|
// Desktop flow: exchange code for token, then redirect via deep link
|
|
api
|
|
.googleLogin(code, redirectUri)
|
|
.then(({ token }) => {
|
|
setDesktopToken(token);
|
|
window.location.href = `multica://auth/callback?token=${encodeURIComponent(token)}`;
|
|
})
|
|
.catch((err) => {
|
|
setError(err instanceof Error ? err.message : "Login failed");
|
|
});
|
|
} else {
|
|
// Normal web flow
|
|
loginWithGoogle(code, redirectUri)
|
|
.then(async (loggedInUser) => {
|
|
const wsList = await api.listWorkspaces();
|
|
qc.setQueryData(workspaceKeys.list(), wsList);
|
|
const onboarded = loggedInUser.onboarded_at != null;
|
|
// Workspace presence beats onboarding state: an invitee with zero
|
|
// `onboarded_at` but a real workspace must land in that workspace,
|
|
// not in the new-workspace wizard. A `next=` (e.g. /invite/<id>)
|
|
// always wins so invite acceptance flows survive auth round-trips.
|
|
router.push(
|
|
nextUrl || resolvePostAuthDestination(wsList, onboarded),
|
|
);
|
|
})
|
|
.catch((err) => {
|
|
setError(err instanceof Error ? err.message : "Login failed");
|
|
});
|
|
}
|
|
}, [searchParams, loginWithGoogle, router, qc]);
|
|
|
|
if (desktopToken) {
|
|
return (
|
|
<div className="flex min-h-screen items-center justify-center">
|
|
<Card className="w-full max-w-sm">
|
|
<CardHeader className="text-center">
|
|
<CardTitle className="text-2xl">Opening Multica</CardTitle>
|
|
<CardDescription>
|
|
You should see a prompt to open the Multica desktop app. If
|
|
nothing happens, click the button below.
|
|
</CardDescription>
|
|
</CardHeader>
|
|
<CardContent className="flex justify-center">
|
|
<Button
|
|
variant="outline"
|
|
onClick={() => {
|
|
window.location.href = `multica://auth/callback?token=${encodeURIComponent(desktopToken)}`;
|
|
}}
|
|
>
|
|
Open Multica Desktop
|
|
</Button>
|
|
</CardContent>
|
|
</Card>
|
|
</div>
|
|
);
|
|
}
|
|
|
|
if (error) {
|
|
return (
|
|
<div className="flex min-h-screen items-center justify-center">
|
|
<Card className="w-full max-w-sm">
|
|
<CardHeader className="text-center">
|
|
<CardTitle className="text-2xl">Login Failed</CardTitle>
|
|
<CardDescription>{error}</CardDescription>
|
|
</CardHeader>
|
|
<CardContent className="flex justify-center">
|
|
<a href={paths.login()} className="text-primary underline-offset-4 hover:underline">
|
|
Back to login
|
|
</a>
|
|
</CardContent>
|
|
</Card>
|
|
</div>
|
|
);
|
|
}
|
|
|
|
return (
|
|
<div className="flex min-h-screen items-center justify-center">
|
|
<Card className="w-full max-w-sm">
|
|
<CardHeader className="text-center">
|
|
<CardTitle className="text-2xl">Signing in...</CardTitle>
|
|
<CardDescription>Please wait while we complete your login</CardDescription>
|
|
</CardHeader>
|
|
<CardContent className="flex justify-center">
|
|
<Loader2 className="h-6 w-6 animate-spin text-muted-foreground" />
|
|
</CardContent>
|
|
</Card>
|
|
</div>
|
|
);
|
|
}
|
|
|
|
export default function CallbackPage() {
|
|
return (
|
|
<Suspense fallback={null}>
|
|
<CallbackContent />
|
|
</Suspense>
|
|
);
|
|
}
|