mirror of
https://github.com/go-gitea/gitea.git
synced 2026-07-20 07:44:01 -05:00
Logging out redirects to front page #11077
Open
opened 2025-11-02 09:26:55 -06:00 by GiteaMirror
·
9 comments
No Branch/Tag Specified
main
release/v1.25
release/v1.24
release/v1.23
release/v1.22
release/v1.21
release/v1.20
release/v1.19
release/v1.18
release/v1.17
release/v1.16
release/v1.15
release/v1.14
release/v1.13
release/v1.12
release/v1.11
release/v1.10
release/v1.9
release/v1.8
v1.25.3
v1.25.2
v1.25.1
v1.25.0
v1.24.7
v1.25.0-rc0
v1.26.0-dev
v1.24.6
v1.24.5
v1.24.4
v1.24.3
v1.24.2
v1.24.1
v1.24.0
v1.23.8
v1.24.0-rc0
v1.25.0-dev
v1.23.7
v1.23.6
v1.23.5
v1.23.4
v1.23.3
v1.23.2
v1.23.1
v1.23.0
v1.23.0-rc0
v1.24.0-dev
v1.22.6
v1.22.5
v1.22.4
v1.22.3
v1.22.2
v1.22.1
v1.22.0
v1.23.0-dev
v1.22.0-rc1
v1.21.11
v1.22.0-rc0
v1.21.10
v1.21.9
v1.21.8
v1.21.7
v1.21.6
v1.21.5
v1.21.4
v1.21.3
v1.21.2
v1.20.6
v1.21.1
v1.21.0
v1.21.0-rc2
v1.21.0-rc1
v1.20.5
v1.22.0-dev
v1.21.0-rc0
v1.20.4
v1.20.3
v1.20.2
v1.20.1
v1.20.0
v1.19.4
v1.21.0-dev
v1.20.0-rc2
v1.20.0-rc1
v1.20.0-rc0
v1.19.3
v1.19.2
v1.19.1
v1.19.0
v1.19.0-rc1
v1.20.0-dev
v1.19.0-rc0
v1.18.5
v1.18.4
v1.18.3
v1.18.2
v1.18.1
v1.18.0
v1.17.4
v1.18.0-rc1
v1.19.0-dev
v1.18.0-rc0
v1.17.3
v1.17.2
v1.17.1
v1.17.0
v1.17.0-rc2
v1.16.9
v1.17.0-rc1
v1.18.0-dev
v1.16.8
v1.16.7
v1.16.6
v1.16.5
v1.16.4
v1.16.3
v1.16.2
v1.16.1
v1.16.0
v1.15.11
v1.17.0-dev
v1.16.0-rc1
v1.15.10
v1.15.9
v1.15.8
v1.15.7
v1.15.6
v1.15.5
v1.15.4
v1.15.3
v1.15.2
v1.15.1
v1.14.7
v1.15.0
v1.15.0-rc3
v1.14.6
v1.15.0-rc2
v1.14.5
v1.16.0-dev
v1.15.0-rc1
v1.14.4
v1.14.3
v1.14.2
v1.14.1
v1.14.0
v1.13.7
v1.14.0-rc2
v1.13.6
v1.13.5
v1.14.0-rc1
v1.15.0-dev
v1.13.4
v1.13.3
v1.13.2
v1.13.1
v1.13.0
v1.12.6
v1.13.0-rc2
v1.14.0-dev
v1.13.0-rc1
v1.12.5
v1.12.4
v1.12.3
v1.12.2
v1.12.1
v1.11.8
v1.12.0
v1.11.7
v1.12.0-rc2
v1.11.6
v1.12.0-rc1
v1.13.0-dev
v1.11.5
v1.11.4
v1.11.3
v1.10.6
v1.12.0-dev
v1.11.2
v1.10.5
v1.11.1
v1.10.4
v1.11.0
v1.11.0-rc2
v1.10.3
v1.11.0-rc1
v1.10.2
v1.10.1
v1.10.0
v1.9.6
v1.9.5
v1.10.0-rc2
v1.11.0-dev
v1.10.0-rc1
v1.9.4
v1.9.3
v1.9.2
v1.9.1
v1.9.0
v1.9.0-rc2
v1.10.0-dev
v1.9.0-rc1
v1.8.3
v1.8.2
v1.8.1
v1.8.0
v1.8.0-rc3
v1.7.6
v1.8.0-rc2
v1.7.5
v1.8.0-rc1
v1.9.0-dev
v1.7.4
v1.7.3
v1.7.2
v1.7.1
v1.7.0
v1.7.0-rc3
v1.6.4
v1.7.0-rc2
v1.6.3
v1.7.0-rc1
v1.7.0-dev
v1.6.2
v1.6.1
v1.6.0
v1.6.0-rc2
v1.5.3
v1.6.0-rc1
v1.6.0-dev
v1.5.2
v1.5.1
v1.5.0
v1.5.0-rc2
v1.5.0-rc1
v1.5.0-dev
v1.4.3
v1.4.2
v1.4.1
v1.4.0
v1.4.0-rc3
v1.4.0-rc2
v1.3.3
v1.4.0-rc1
v1.3.2
v1.3.1
v1.3.0
v1.3.0-rc2
v1.3.0-rc1
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.2.0-rc3
v1.2.0-rc2
v1.1.4
v1.2.0-rc1
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.99
Labels
Clear labels
$20
$250
$50
$500
backport/done
💎 Bounty
docs-update-needed
good first issue
hacktoberfest
issue/bounty
issue/confirmed
issue/critical
issue/duplicate
issue/needs-feedback
issue/not-a-bug
issue/regression
issue/stale
issue/workaround
lgtm/need 2
modifies/api
modifies/translation
outdated/backport/v1.18
outdated/theme/markdown
outdated/theme/timetracker
performance/bigrepo
performance/cpu
performance/memory
performance/speed
pr/breaking
proposal/accepted
proposal/rejected
pr/wip
pull-request
reviewed/wontfix
💰 Rewarded
skip-changelog
status/blocked
topic/accessibility
topic/api
topic/authentication
topic/build
topic/code-linting
topic/commit-signing
topic/content-rendering
topic/deployment
topic/distribution
topic/federation
topic/gitea-actions
topic/issues
topic/lfs
topic/mobile
topic/moderation
topic/packages
topic/pr
topic/projects
topic/repo
topic/repo-migration
topic/security
topic/theme
topic/ui
topic/ui-interaction
topic/ux
topic/webhooks
topic/wiki
type/bug
type/deprecation
type/docs
type/enhancement
type/feature
type/miscellaneous
type/proposal
type/question
type/refactoring
type/summary
type/testing
type/upstream
Mirrored from GitHub Pull Request
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/gitea#11077
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @drsybren on GitHub (Jun 22, 2023).
Description
Logging out always redirects you to the front page.
Screenshots
This is about redirects, can't really be captured in a screenshot.
Gitea Version
1.20.0+dev-1026-ge29ab5442
Can you reproduce the bug on the Gitea demo site?
Yes
Operating System
No response
Browser Version
Brave 1.52.126
@silverwind commented on GitHub (Jun 22, 2023):
It could be that the repo is private, in which case staying on the URL would result in a 404 error. I think that is the reason for the redirect.
Generally I think that the login page should not have its own URL and just be shown dynamically based on authentication need, avoiding the need for all related redirects, but I recall some people were against this behaviour.
@drsybren commented on GitHub (Jun 22, 2023):
That could very well be, but it's still annoying and unnecessary. And as I put in my report, this happens for non-private repositories as well.
Also a 404 would be the wrong code to indicate an access issue, and 403 Forbidden would be more appropriate. And for me it would be perfectly fine to see an "forbidden" message when I just logged out.
The redirects are fine, as long as they direct you to the appropriate place.
@delvh commented on GitHub (Jun 22, 2023):
Unfortunately, that's not possible:
The 404 for that is deliberate for security reasons, otherwise you will always know if a repo doesn't exist or if you don't have permission to view it.
@drsybren commented on GitHub (Jun 22, 2023):
That reeks of security by obscurity, but this is not the place to discuss that.
Between the two login/logout/redirect-related issues I filed today (this one and #25435), #25435 is the more common one for me to be hindered by, though.
@silverwind commented on GitHub (Jun 22, 2023):
In any case, as already mentioned, I think the solution to this and https://github.com/go-gitea/gitea/issues/25435 is to just not alter existing URL path and query parameters when user clicks the login button.
E.g. user clicks the "Login" button, sends a
?login=truequery to the current page URL, backend renders login page because it reacts on theloginparameter and on success redirects to the same page path and query with theloginquery parameter removed.That mechanism should be compatible with current standalone
/user/loginpage, but I guess iedally the standalone login page should be removed completely and replaced by thislogin=truemechanism.@puni9869 commented on GitHub (Jul 21, 2023):
Can we close this ISSUE if it is done.
@lunny commented on GitHub (Jul 21, 2023):
https://github.com/go-gitea/gitea/pull/25522#issuecomment-1607491968
@lunny commented on GitHub (Mar 27, 2024):
I think this is a design problem rather than a bug.
@n1tehawk commented on GitHub (Apr 8, 2024):
Replying here, since #25522 is locked.
I'm also a bit unhappy with the change in that PR, as it looks like a bit of a regression to me. Why? Before that change, users had the opportunity to change the redirection URL via customization of
templates/base/head_navbar.tmpl, namely thedata-redirect="..."attribute in the link tag. After #25522 got applied, the destination is now always theAppSubURL(gitea "home page").So while https://github.com/go-gitea/gitea/pull/25522#issuecomment-1607491968 might apply in theory
in reality there currently seems to be no real choice.
It matters to me because im using gitea for a private repo site in conjunction with "single sign-on" via NextCloud as an OAuth2 provider. In the past it was easy to customize the logout to return the users to the cloud dashboard / start page (where they would have a link to return to the code site if desired). But now they land on the gitea home page and have to navigate / find their way back to the cloud manually...
It would be nice if this logic could be changed / extended in a way that would allow to specify the destination URL again - either via some template attribute, or maybe some dedicated (app.ini) configuration setting.
Regards, NiteHawk