fix login bug

This commit is contained in:
JCEEE
2026-09-07 17:45:17 +01:00
parent a959f204bd
commit 7ced424a36
2 changed files with 13 additions and 1 deletions
@@ -1,3 +1,4 @@
import { redirect } from '@sveltejs/kit';
import { createPbClient } from '$lib/server/pocketbase'; import { createPbClient } from '$lib/server/pocketbase';
import { createServices, type ChatActor } from '$lib/server/services'; import { createServices, type ChatActor } from '$lib/server/services';
import { ensureFamAccess } from '$lib/server/access'; import { ensureFamAccess } from '$lib/server/access';
@@ -63,6 +64,17 @@ export async function load(event) {
fam = res.fam; fam = res.fam;
famAccess = res.access; famAccess = res.access;
} }
// Canonical URL: the [fam] segment must be the family SLUG, never the PB
// id. If someone lands on /{famId}/... (a stale shortcut, bookmark, or a
// login that fell back to the id), rewrite the first path segment to the
// slug so the id is replaced everywhere it'd otherwise persist.
const paramFam = event.params.fam;
const canonicalSlug = fam?.slug;
if (canonicalSlug && paramFam && paramFam !== canonicalSlug) {
const rest = event.url.pathname.replace(`/${paramFam}`, '') || '/';
const qs = event.url.search;
throw redirect(303, `/${encodeURIComponent(canonicalSlug)}${rest}${qs}`);
}
} }
return { return {
+1 -1
View File
@@ -117,7 +117,7 @@
$effect(() => { $effect(() => {
if (!page.data.session) return; if (!page.data.session) return;
recordShortcut({ recordShortcut({
famSlug: page.params.fam || '', famSlug: (page.data.fam?.slug as string) || page.params.fam || '',
famName: (page.data.fam?.name as string) || page.params.fam || '', famName: (page.data.fam?.name as string) || page.params.fam || '',
userName: page.data.role === 'parent' ? '' : page.params.username || '' userName: page.data.role === 'parent' ? '' : page.params.username || ''
}); });