mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 11:12:35 +02:00
ProtectedRoute and PermissionRoute now pass the requested location as router state when redirecting to /login. LoginPage stashes it in sessionStorage before the OIDC provider redirect (since window.location kills React state) and consumes it on all three post-login navigations (credentials, 2FA, OIDC token exchange). Targets are sanitized to same-origin internal paths only — protocol-relative and /login itself are rejected to prevent open-redirect. QR labels (https://host/inventory?spool=N) now land on the scanned spool instead of the printer page after authentik / any OIDC SSO login.