import { describe, expect, it } from "vitest"; import { safeAuthReturnPath } from "./return-path"; describe("public auth return path", () => { it("keeps site-local destinations", () => { expect(safeAuthReturnPath("/commission/tickets?from=login")).toBe("/commission/tickets?from=login"); }); it("rejects external destinations and auth loops", () => { for (const value of ["https://example.com", "//example.com", "/\\example.com", "/login", "/lo%67in", "/register", "/auth/login", "/auth/register", "/auth/check-email", "/auth/password-reset", "/admin/login", 4]) expect(safeAuthReturnPath(value)).toBe("/"); }); });