diff --git a/src/features/kullanici/components/giris-linki.tsx b/src/features/kullanici/components/giris-linki.tsx index c9b9358..ccdbc75 100644 --- a/src/features/kullanici/components/giris-linki.tsx +++ b/src/features/kullanici/components/giris-linki.tsx @@ -21,11 +21,23 @@ import { Button } from "@/components/ui/button"; * ediliyor — cacheComponents açıkken dinamik parametreli rotalarda gereken * sınır hazır (next/dist/docs/.../use-pathname.md). */ +/** + * better-auth (1.6.23) callback'i kendi göreli-yol kalkanından geçiriyor: + * `^\/(?!\/|\\|%2f|%5c)[\w\-.+/@]*(?:\?…)?$`. `\w` ASCII olduğu için + * `/rehber/ösym` ya da yüzde-kodlanmış `/bolum/t%C4%B1p` gibi yollar + * **403 INVALID_CALLBACK_URL** ile reddediliyor ve kullanıcı o sayfadan hiç + * giriş yapamıyor (main'de callback hep "/" olduğu için bu yol yoktu). + * Bu yüzden callback'i ancak auth katmanının da kabul edeceği yollarda + * takıyoruz; gerisinde sade /giris'e düşüyoruz — bağlam kaybı, kırık giriş + * akışına yeğdir. Kalkan daraltılırsa (tek yer) buradaki de gevşetilebilir. + */ +const AUTH_GUVENLI_YOL = /^\/(?!\/|\\)[\w\-./+@]*$/; + export function GirisLinki() { const pathname = usePathname(); // /giris kendine callback veremez (döngü); pathname yoksa sade hedef. const href = - pathname && !pathname.startsWith("/giris") + pathname && !pathname.startsWith("/giris") && AUTH_GUVENLI_YOL.test(pathname) ? `/giris?callback=${encodeURIComponent(pathname)}` : "/giris";