From 32f3998d6c7685a94ab31ec9dabfb2e02f9dba23 Mon Sep 17 00:00:00 2001 From: itsrubberduck Date: Tue, 28 Jul 2026 19:37:27 +0200 Subject: [PATCH] fix(routing): catch the paths the split left pointing at nothing MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Three dead ends, one cause: these routes resolved to pages that stayed on the website, and nothing here answered them any more. /start — this page became the app's front page in the split (it is index.vue now), so every pre-split bookmark and the website's own redirect landed on a 404. Caught here so the app's old URLs work without waiting for the website to be redeployed. /login — the app has no login by design, identity comes from the issuer. But five call sites still send people there: logout, the live-atc session guard, the bridge pairing screen. In the monorepo that path was the website's login form; since the split it was nothing, so signing out dropped the user on a blank page. It is a forwarder to the issuer, not a login form. /logout — after clearing the app session it sent the user to /login, which under SSO means an issuer where they are still signed in: they would be handed a fresh code and land straight back inside. It now signs them out at the issuer too, which bumps tokenVersion and invalidates every refresh token. Co-Authored-By: Claude Opus 5 --- app/pages/login.vue | 28 ++++++++++++++++++++++++++++ app/pages/logout.vue | 13 ++++++++++++- 2 files changed, 40 insertions(+), 1 deletion(-) create mode 100644 app/pages/login.vue diff --git a/app/pages/login.vue b/app/pages/login.vue new file mode 100644 index 0000000..ecc1674 --- /dev/null +++ b/app/pages/login.vue @@ -0,0 +1,28 @@ + diff --git a/app/pages/logout.vue b/app/pages/logout.vue index 31b28bd..99061d4 100644 --- a/app/pages/logout.vue +++ b/app/pages/logout.vue @@ -21,6 +21,7 @@ import { useAuthStore } from '~/stores/auth' const router = useRouter() const auth = useAuthStore() +const config = useRuntimeConfig() useHead({ title: 'Logout – OpenSquawk', @@ -31,7 +32,17 @@ useHead({ onMounted(async () => { await auth.logout() - router.replace('/login') + + // Sign out at the issuer too. Sending the user to the app's own /login would + // only forward them back to an issuer where they are still signed in — they + // would be handed a fresh code and land straight back inside, which is not + // what "log out" means. + const issuer = String(config.public.authIssuer || '').replace(/\/+$/, '') + if (issuer) { + return navigateTo(`${issuer}/logout`, { external: true }) + } + + router.replace('/') })