Commit Graph
2 Commits
Author SHA1 Message Date
ca971413e9 fix(web): allow user-activated top navigation for custom home iframe (#5955)
The custom home page URL iframe only allows allow-forms/allow-popups/
allow-popups-to-escape-sandbox/allow-scripts, without allow-top-navigation*.
As a result, target="_top" nav/menu links inside the (admin-configured,
trusted) embedded page cannot navigate the top-level window on desktop
browsers, while some mobile browsers still allow it via allow-popups —
causing inconsistent behavior rather than an intended restriction.

Add allow-top-navigation-by-user-activation so user-clicked top-level
links work consistently across devices. This token only permits
user-activated top navigation and does NOT grant same-origin access,
so it avoids the security concern of allow-same-origin.

Co-authored-by: 贺. <kuang@M1.local>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-11 10:52:17 +08:00
乾Land贺. 3a876d6f31 fix(web): redirect authenticated users away from sign-up page (#5910)
The sign-in route already redirects logged-in users to /dashboard in its
beforeLoad guard, but the sign-up route (and its /register alias) had no
such guard, leaving authenticated users on the registration form. This
mirrors the classic theme's AuthRedirect behavior. Add an equivalent
beforeLoad guard using the same useAuthStore, redirecting to /dashboard
for consistency with the sign-in route.

Closes #5908

Co-authored-by: 贺. <kuang@M1.local>
2026-07-06 14:57:36 +08:00