Logging in returns to the page that was asked for (closes #384)
check / check (push) Waiting to run

A logged-out GET of an admin page now redirects to /pages/login with its path and query in a next parameter, when they fit in 2048 bytes. The login form carries next as a hidden field; a successful login redirects there, and a failed one shows the page again with the same next. A POST still redirects to plain /pages/login.

The value is client-chosen, so every read of it goes through one check: after percent-decoding it must start with exactly one / and contain no backslash or control character; anything else becomes /. gosec's open-redirect rule is suppressed on the two redirects that follow it. The login page's navigation bar no longer links to itself.

Model: opus-5-5
This commit was merged in pull request #406.
This commit is contained in:
2026-10-02 06:57:51 +02:00
parent 803a94be37
commit 7d360babed
10 changed files with 406 additions and 15 deletions
+1
View File
@@ -24,6 +24,7 @@
<form method="POST" action="/pages/login" class="space-y-6">
<input type="hidden" name="csrf_token" value="{{.CSRFToken}}">
<input type="hidden" name="next" value="{{.Next}}">
<div class="form-group">
<label for="username" class="label">Username</label>
<input