Skip to content

[fix] 舊網址轉址到字面上的 /dashboard/<頁面>/:path*,導致登入 INVALID_CALLBACK_URL - #75

Closed
Lanznx wants to merge 1 commit into
mainfrom
claude/fix-dashboard-redirect-root
Closed

Lanznx wants to merge 1 commit into
mainfrom
claude/fix-dashboard-redirect-root

Conversation

@Lanznx

@Lanznx Lanznx commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

問題

從舊網址(例如 https://internal.pathors.com/settings)進站登入時,Google 登入按下去直接跳「Invalid callbackURL」。

prod 現況:

舊網址 轉到
/settings /dashboard/settings/:path* ❌(字面上的 :path*)
/contracts /dashboard/contracts/:path* ❌
/settings/foo /dashboard/settings/foo ✅

MOVED_TO_DASHBOARD 裡的 18 個頁面,只要舊網址後面沒接子路徑就都會壞掉。

原因

flowchart LR
  A["/settings"] -->|"308(OpenNext 沒代換 :path*)"| B["/dashboard/settings/:path*"]
  B -->|"proxy:未登入"| C["/login?redirect=/dashboard/settings/:path*"]
  C -->|"signIn.social callbackURL"| D["better-auth origin check<br/>含 : 與 * → INVALID_CALLBACK_URL"]
Loading
  • 這條 redirects() 規則是 [feature] 邀請過期可見化、MCP 上架 metadata、landing page 與 /dashboard 搬移、交易幣別綁定帳戶 #49 搬 /dashboard 時加的:/${segment}/:path* → /dashboard/${segment}/:path*。照 Next 的規格沒寫錯。
  • 但部署在 Workers 上時,@opennextjs/aws 的 matcher(core/routing/matcher.js)只有在 source 抓到至少一個參數時(isUsingParams)才會把 destination 丟進 compile()。/settings 的 :path* 抓到零段,沒有參數,destination 就原字照回。
  • better-auth 的相對路徑白名單 regex 不接受 : 和 *,於是回 INVALID_CALLBACK_URL。

Google OAuth client 這邊沒有問題:prod 產生的 authorize URL 實際打過,沒有 redirect_uri_mismatch。

改動

next.config.ts:每個頁面拆成兩條規則。

  • /${segment} → /dashboard/${segment}:沒有參數,不需要代換。
  • /${segment}/:path+ → /dashboard/${segment}/:path+:至少一段,一定有參數,一定會被代換。

驗證

跑 bun run cf:build,再用 wrangler dev --local 起 build 好的 worker 實測:

路徑 結果
/settings 308 → /dashboard/settings ✅
/settings/foo 308 → /dashboard/settings/foo ✅
/contracts 308 → /dashboard/contracts ✅
/contracts/123/edit 308 → /dashboard/contracts/123/edit ✅
/dashboard/settings(未登入) 307 → /login?redirect=%2Fdashboard%2Fsettings ✅
  • 沒有 schema change,不需要 migration。
  • ⚠️ 這些是 308 永久轉址,瀏覽器會快取。已經撞過壞轉址的人,上線後可能還會被帶到舊的錯誤網址,要清快取或直接開 /dashboard/...。

🤖 Generated with Claude Code

…CALLBACK_URL

OpenNext 的 redirect matcher 只在 source 抓到參數時才會代換 destination。
`/:segment/:path*` 對沒有子路徑的網址抓到零段,destination 原字照回;
沒登入時這串被帶進 /login 的 callbackURL,better-auth 驗不過。
拆成 `/segment` 與 `/segment/:path+` 兩條。

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Lanznx

Lanznx commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

@yui0303 AI check 沒問題,可以 review/merge 🙏 (只改 next.config.ts 的 redirects,修舊網址 /settings 等登入時的 INVALID_CALLBACK_URL;已用 cf:build + wrangler 本機驗過)

@github-actions

Copy link
Copy Markdown

✅ SonarQube Quality Gate passed — pathorsAI_internal

0 open issues on this PR.

@Lanznx Lanznx closed this Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant