Skip to content

fix(auth): use router.replace for protected-page login redirects (#46) - #199

Merged
presidojay1 merged 2 commits into
StellarTickets:mainfrom
richardtoms100:fix/46-auth-redirect-replace
Sep 26, 2026
Merged

presidojay1 merged 2 commits into
StellarTickets:mainfrom
richardtoms100:fix/46-auth-redirect-replace

Conversation

@richardtoms100

@richardtoms100 richardtoms100 commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

Every protected page redirected signed-out users with router.push('/login') in an effect. push leaves the protected URL in history, so pressing Back from /login returned to the protected page, which immediately pushed /login again. The user could never go back past it.

Fix

Commit 1: src/lib/use-require-auth.ts (new) + tests

export function useRequireAuth(to: string = LOGIN_PATH): void {
  const { user, loading } = useAuth();
  const router = useRouter();
  useEffect(() => {
    if (!loading && !user) router.replace(to);
  }, [loading, user, router, to]);
}

This is the protected-page counterpart to useRedirectIfAuthenticated (#50 / #198), which already uses router.replace for the guest-only pages. The two redirect directions now share the same pattern.

Commit 2: adopt it on all six protected pages

Page Before After
dashboard router.push('/login') effect useRequireAuth()
dashboard/organizations/[id] router.push("/login") effect useRequireAuth()
dashboard/events/[id] router.push('/login') effect useRequireAuth()
my-tickets router.push('/login') effect useRequireAuth()
verify router.push('/login') effect useRequireAuth()
marketplace router.push('/login') effect useRequireAuth()

The router / useRouter / useEffect imports that each page no longer uses were removed (none of these pages used router for anything else). grep confirms no push('/login') is left in src/.

Tests: src/lib/use-require-auth.test.ts (5)

  • A signed-out user → router.replace('/login'), and router.push is never called. This is the regression guard for Auth redirects use router.push, trapping the browser Back button #46.
  • No redirect while auth is still loading.
  • No redirect for a signed-in user.
  • Redirects exactly once when loading finishes without a user.
  • A custom destination is supported.

The repo has no @testing-library/react, so the tests mount a probe component with react-dom/client + act under the existing jsdom Vitest config, with next/navigation and auth-context mocked.

Verification

  • npx vitest run: 15 files, 71/71 tests pass, including the 5 new ones.
  • eslint is clean on the changed pages and the new files.
  • tsc --noEmit shows no errors from this change.

⚠️ Pre-existing issue on main (not touched here)

src/app/my-tickets/page.tsx already fails to parse on main, before this PR (tsc: TS17008 JSX element 'div' has no corresponding closing tag around line 274/329). It looks like a merge left the View on-chain <a> block without its wrapping conditional's closing. This PR's change to that file is only the 7-line redirect swap near the top. The JSX breakage should be fixed separately, because it will fail next build regardless of this PR.
Closes #46
Closes #47
Closes #48

Closes #49

Protected-page counterpart to useRedirectIfAuthenticated (StellarTickets#50): once auth
has loaded and there is no user, router.replace('/login') so the
protected URL isn't left in history.

Refs StellarTickets#46
Replace the per-page router.push('/login') effects in dashboard,
dashboard/organizations/[id], dashboard/events/[id], my-tickets, verify
and marketplace with useRequireAuth(), which uses router.replace, so the
protected URL is not left in history. Drops now-unused useRouter /
useEffect imports.

Closes StellarTickets#46
@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@richardtoms100 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@netlify

netlify Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

❌ Deploy Preview for stellartickets failed.

Name Link
🔨 Latest commit a781cc8
🔍 Latest deploy log https://app.netlify.com/projects/stellartickets/deploys/6ab804fb3466ee00085aa012

@presidojay1
presidojay1 merged commit 1c6b90d into StellarTickets:main Sep 26, 2026
0 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants