13 lines
459 B
TypeScript
13 lines
459 B
TypeScript
export function safeAuthReturnPath(value: unknown): string {
|
|
if (typeof value !== "string" || !value.startsWith("/")) return "/";
|
|
try {
|
|
const url = new URL(value, "https://auth.local");
|
|
const path = decodeURIComponent(url.pathname);
|
|
if (url.origin !== "https://auth.local" || ["/login", "/register", "/commission/login"].includes(path))
|
|
return "/";
|
|
return `${url.pathname}${url.search}${url.hash}`;
|
|
} catch {
|
|
return "/";
|
|
}
|
|
}
|